ZERO-DAY 2026 2025 2024 2023 | PUBLISHED | UPCOMING
|
ZDI-CAN-30585
|
PAX Technology
|
|
7.5
|
2026-08-05
|
2026-08-05
|
(0Day) PAX Technology Q80 Application Installer
Signature Verification Bypass Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-30583
|
PAX Technology
|
|
7.5
|
2026-08-05
|
2026-08-05
|
(0Day) PAX Technology Q80 AIP File Parsing Link
Following Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-30584
|
PAX Technology
|
|
7.1
|
2026-08-05
|
2026-08-05
|
(0Day) PAX Technology Q80 XCB Daemon Missing
Authentication Vulnerability
|
||
|
ZDI-CAN-27987
|
Hugging Face
|
CVE-2026-15679
|
7.8
|
2026-07-30
|
2026-07-30
|
Hugging Face PyTorch Image Models checkpoint
Deserialization of Untrusted Data Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-27763
|
Phoenix Contact
|
CVE-2026-41032
|
6.5
|
2026-07-30
|
2026-07-30
|
Phoenix Contact CHARX SEC-3000 Insertion of
Sensitive Information into Log File Information Disclosure
Vulnerability
|
||
|
ZDI-CAN-27762
|
Phoenix Contact
|
CVE-2026-44095
|
6.8
|
2026-07-30
|
2026-07-30
|
Phoenix Contact CHARX SEC-3000 Command Injection
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29093
|
Phoenix Contact
|
CVE-2026-44103
|
7.5
|
2026-07-30
|
2026-07-30
|
(Pwn2Own) Phoenix Contact CHARX SEC-3150 Jupicore
External Control of Path Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29077
|
Phoenix Contact
|
CVE-2026-44099
|
7.5
|
2026-07-30
|
2026-07-30
|
(Pwn2Own) Phoenix Contact CHARX SEC-3150
CharxSystemConfigManager Configuration Injection Remote Code
Execution Vulnerability
|
||
|
ZDI-CAN-29073
|
Phoenix Contact
|
CVE-2026-44091
|
6.3
|
2026-07-30
|
2026-07-30
|
(Pwn2Own) Phoenix Contact CHARX SEC-3150 MQTT
Service Server-Side Request Forgery Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-29054
|
Phoenix Contact
|
CVE-2026-44098
|
6.8
|
2026-07-30
|
2026-07-30
|
(Pwn2Own) Phoenix Contact CHARX SEC-3150
BackendURL WebSocket Command Injection Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-29055
|
Phoenix Contact
|
CVE-2026-44090
|
6.5
|
2026-07-30
|
2026-07-30
|
(Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus
Server Exposed Dangerous Function Denial-of-Service
Vulnerability
|
||
|
ZDI-CAN-28999
|
Phoenix Contact
|
CVE-2026-44100
|
4.2
|
2026-07-30
|
2026-07-30
|
(Pwn2Own) Phoenix Contact CHARX SEC-3150 charx-jupicore
Missing Authentication Configuration Modification Vulnerability
|
||
|
ZDI-CAN-29076
|
Phoenix Contact
|
CVE-2026-44094
|
7.5
|
2026-07-30
|
2026-07-30
|
(Pwn2Own) Phoenix Contact CHARX SEC-3150 Failing
Open Authentication Bypass Vulnerability
|
||
|
ZDI-CAN-29110
|
Phoenix Contact
|
CVE-2026-44097
|
2.4
|
2026-07-30
|
2026-07-30
|
(Pwn2Own) Phoenix Contact CHARX SEC-3150 update2-upload
Arbitrary File Upload Vulnerability
|
||
|
ZDI-CAN-29052
|
Phoenix Contact
|
CVE-2026-44107
|
6.5
|
2026-07-30
|
2026-07-30
|
(Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus
Server Exposed Dangerous Function Denial-of-Service
Vulnerability
|
||
|
ZDI-CAN-29075
|
Phoenix Contact
|
CVE-2026-44093
|
7.8
|
2026-07-30
|
2026-07-30
|
(Pwn2Own) Phoenix Contact CHARX SEC-3150
user-applications Symlink Following Local Privilege Escalation
Vulnerability
|
||
|
ZDI-CAN-29094
|
Phoenix Contact
|
CVE-2026-44104
|
7.5
|
2026-07-30
|
2026-07-30
|
(Pwn2Own) Phoenix Contact CHARX SEC-3150 Missing
Cryptographic Signature Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29091
|
Phoenix Contact
|
CVE-2026-44101
|
5.0
|
2026-07-30
|
2026-07-30
|
(Pwn2Own) Phoenix Contact CHARX SEC-3150 OCPP
Missing Authentication for Critical Function Authentication
Bypass Vulnerability
|
||
|
ZDI-CAN-29108
|
Phoenix Contact
|
CVE-2026-44095
|
7.8
|
2026-07-30
|
2026-07-30
|
(Pwn2Own) Phoenix Contact CHARX SEC-3150
charx_set_ip_address Improper Input Validation Local Privilege
Escalation Vulnerability
|
||
|
ZDI-CAN-29109
|
Phoenix Contact
|
CVE-2026-44096
|
7.8
|
2026-07-30
|
2026-07-30
|
(Pwn2Own) Phoenix Contact CHARX SEC-3150
Privilege Defined With Unsafe Actions Local Privilege Escalation
Vulnerability
|
||
|
ZDI-CAN-29050
|
Phoenix Contact
|
CVE-2026-44105
|
5.3
|
2026-07-30
|
2026-07-30
|
(Pwn2Own) Phoenix Contact CHARX SEC-3150
Insertion of Sensitive Information into Log File Authentication
Bypass Vulnerability
|
||
|
ZDI-CAN-29074
|
Phoenix Contact
|
CVE-2026-44092
|
5.0
|
2026-07-30
|
2026-07-30
|
(Pwn2Own) Phoenix Contact CHARX SEC-3150
charx-system-config-manager Service CRLF Injection Firewall
Bypass Vulnerability
|
||
|
ZDI-CAN-29059
|
Phoenix Contact
|
CVE-2026-7849
|
7.5
|
2026-07-30
|
2026-07-30
|
(Pwn2Own) Phoenix Contact CHARX SEC-3150
CharxSystemConfigManager Configuration Injection Remote Code
Execution Vulnerability
|
||
|
ZDI-CAN-29058
|
Phoenix Contact
|
CVE-2026-44108
|
6.4
|
2026-07-30
|
2026-07-30
|
(Pwn2Own) Phoenix Contact CHARX SEC-3150 Race
Condition Firewall Bypass Vulnerability
|
||
|
ZDI-CAN-29085
|
Phoenix Contact
|
CVE-2026-44106
|
7.8
|
2026-07-30
|
2026-07-30
|
(Pwn2Own) Phoenix Contact CHARX SEC-3150
user-applications Link Following Local Privilege Escalation
Vulnerability
|
||
|
ZDI-CAN-31457
|
WatchGuard
|
CVE-2026-13054
|
7.2
|
2026-07-29
|
2026-07-29
|
WatchGuard FireWare OS sigd comp_start_cb
Directory Traversal Arbitrary File Creation Vulnerability
|
||
|
ZDI-CAN-31458
|
WatchGuard
|
CVE-2026-13050
|
7.2
|
2026-07-29
|
2026-07-29
|
WatchGuard FireWare OS networkd
network_wireless_kick_off_user_cb Stack-based Buffer Overflow
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-31459
|
WatchGuard
|
CVE-2026-13053
|
4.7
|
2026-07-29
|
2026-07-29
|
WatchGuard FireWare OS cli Token Parser
Stack-based Buffer Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28122
|
Trend Micro
|
CVE-2025-71387
|
7.2
|
2026-07-29
|
2026-07-29
|
TrendAI Vision One Incorrect Privilege Assignment
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28148
|
Trend Micro
|
CVE-2025-71386
|
7.7
|
2026-07-29
|
2026-07-29
|
TrendAI Vision One Service Gateway Logs
Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28718
|
TrendLife
|
CVE-2026-62660
|
5.6
|
2026-07-29
|
2026-08-05
|
Trend AI Cleaner One Pro Link Following Arbitrary
File Deletion Vulnerability
|
||
|
ZDI-CAN-31293
|
VMware
|
CVE-2026-47876
|
8.2
|
2026-07-29
|
2026-07-29
|
(Pwn2Own) VMware ESXi VMXNET3 espQueueMask
Out-Of-Bounds Write Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-30380
|
Apple
|
CVE-2026-43729
|
7.8
|
2026-07-29
|
2026-07-29
|
Apple macOS USD File Parsing Heap-based Buffer
Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29483
|
Apple
|
CVE-2026-43733
|
7.8
|
2026-07-29
|
2026-07-29
|
Apple macOS USD File Parsing Heap-based Buffer
Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29252
|
Apple
|
CVE-2026-43780
|
7.8
|
2026-07-29
|
2026-07-29
|
Apple macOS ImageIO Numeric Truncation Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-29143
|
Apple
|
CVE-2026-43673
|
8.8
|
2026-07-29
|
2026-07-29
|
Apple macOS CoreAudio Out-Of-Bounds Write Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-29070
|
Kenwood
|
CVE-2026-18273
|
6.6
|
2026-07-29
|
2026-07-29
|
(Pwn2Own) Kenwood DNR1007XR USB Incorrect Default
Permissions Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28981
|
Kenwood
|
CVE-2026-18272
|
6.8
|
2026-07-29
|
2026-07-29
|
(Pwn2Own) Kenwood DNR1007XR startUpdateProcess
Command Injection Vulnerability
|
||
|
ZDI-CAN-28974
|
Kenwood
|
CVE-2026-18271
|
6.8
|
2026-07-29
|
2026-07-29
|
(Pwn2Own) Kenwood DNR1007XR vCardParser
Heap-based Buffer Overflow Code Execution Vulnerability
|
||
|
ZDI-CAN-29111
|
Kenwood
|
CVE-2026-18270
|
7.8
|
2026-07-29
|
2026-07-29
|
(Pwn2Own) Kenwood DNR1007XR udhcpd Incorrect
Permission Assignment Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28980
|
Kenwood
|
CVE-2026-18269
|
6.8
|
2026-07-29
|
2026-07-29
|
(Pwn2Own) Kenwood DNR1007XR tchdr_bytestream_read
Out-Of-Bounds Write Code Execution Vulnerability
|
||
|
ZDI-CAN-29066
|
Kenwood
|
CVE-2026-18268
|
7.0
|
2026-07-29
|
2026-07-29
|
(Pwn2Own) Kenwood DNR1007XR JKGenService Command
Injection Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28751
|
Kenwood
|
CVE-2026-18267
|
6.8
|
2026-07-29
|
2026-07-29
|
(Pwn2Own) Kenwood DNR1007XR Firmware Update Link
Following Code Execution Vulnerability
|
||
|
ZDI-CAN-30634
|
NoMachine
|
CVE-2026-18264
|
8.8
|
2026-07-29
|
2026-07-29
|
NoMachine getstat Command Injection Remote Code
Execution Vulnerability
|
||
|
ZDI-CAN-30687
|
Progress Software
|
CVE-2026-59689
|
8.8
|
2026-07-29
|
2026-07-29
|
Progress Software Kemp LoadMaster enablexroot Use
of Hard-Coded Cryptographic Key Privilege Escalation
Vulnerability
|
||
|
ZDI-CAN-30735
|
Progress Software
|
CVE-2026-59690
|
8.8
|
2026-07-29
|
2026-07-29
|
Progress Software Kemp LoadMaster access Missing
Authorization Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-30036
|
OSNEXUS
|
CVE-2026-18265
|
9.8
|
2026-07-29
|
2026-07-29
|
OSNEXUS QuantaStor Missing Authentication Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-28603
|
Heimdall Data
|
CVE-2026-18274
|
7.2
|
2026-07-29
|
2026-07-29
|
Heimdall Data Database Proxy uploadJar Directory
Traversal Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28201
|
Adminer
|
CVE-2026-15686
|
7.2
|
2026-07-29
|
2026-07-29
|
Adminer multi_query Incorrect Check of Function
Return Value Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29061
|
Sony
|
CVE-2026-18284
|
7.8
|
2026-07-29
|
2026-07-29
|
(Pwn2Own) Sony XAV-9500ES Crash Dump Handler
Command Injection Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28992
|
Sony
|
CVE-2026-18283
|
2.4
|
2026-07-29
|
2026-07-29
|
(Pwn2Own) Sony XAV-9500ES udev USB Rules
Authorization Bypass Vulnerability
|
||
|
ZDI-CAN-28995
|
Sony
|
CVE-2026-18282
|
8.0
|
2026-07-29
|
2026-07-29
|
(Pwn2Own) Sony XAV-9500ES
AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code
Execution Vulnerability
|
||
|
ZDI-CAN-29072
|
Sony
|
CVE-2026-18281
|
8.0
|
2026-07-29
|
2026-07-29
|
(Pwn2Own) Sony XAV-9500ES l2_reassemble_sdu
Heap-based Buffer Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29060
|
Sony
|
CVE-2026-18280
|
3.9
|
2026-07-29
|
2026-07-29
|
(Pwn2Own) Sony XAV-9500ES gpsd Buffer Overflow
Arbitrary Code Execution Vulnerability
|
||
|
ZDI-CAN-29042
|
Sony
|
CVE-2026-18279
|
8.8
|
2026-07-29
|
2026-07-29
|
(Pwn2Own) Sony XAV-9500ES RTSP SETUP Buffer
Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28990
|
Sony
|
CVE-2026-18278
|
3.5
|
2026-07-29
|
2026-07-29
|
(Pwn2Own) Sony XAV-9500ES prh_l2_decode_packet
Out-Of-Bounds Read Information Disclosure Vulnerability
|
||
|
ZDI-CAN-29159
|
aeon
|
CVE-2026-18287
|
7.8
|
2026-07-29
|
2026-07-29
|
Aeon load_time_series_segmentation_benchmark Code
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29160
|
aeon
|
CVE-2026-18286
|
7.8
|
2026-07-29
|
2026-07-29
|
Aeon load_human_activity_segmentation_datasets
Code Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28749
|
aeon
|
CVE-2026-18285
|
7.8
|
2026-07-29
|
2026-07-29
|
Aeon load_rehab_pile_dataset Deserialization of
Untrusted Data Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29787
|
GStreamer
|
CVE-2026-18299
|
7.8
|
2026-07-29
|
2026-07-29
|
GStreamer rtpsbcdepay Use-After-Free Remote Code
Execution Vulnerability
|
||
|
ZDI-CAN-29581
|
GStreamer
|
CVE-2026-18298
|
7.8
|
2026-07-29
|
2026-07-29
|
GStreamer PNG File Parsing Heap-based Buffer
Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29584
|
GStreamer
|
CVE-2026-18297
|
7.8
|
2026-07-29
|
2026-07-29
|
GStreamer OGG File Parsing Stack-based Buffer
Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29608
|
GStreamer
|
CVE-2026-18296
|
7.8
|
2026-07-29
|
2026-07-29
|
GStreamer MRF File Parsing Heap-based Buffer
Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29510
|
GStreamer
|
CVE-2026-18295
|
7.8
|
2026-07-29
|
2026-07-29
|
GStreamer MRF File Parsing Out-Of-Bounds Write
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29401
|
GIMP
|
CVE-2026-18309
|
7.8
|
2026-07-29
|
2026-07-29
|
GIMP APNG File Parsing Integer Overflow Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-29405
|
GIMP
|
CVE-2026-18308
|
7.8
|
2026-07-29
|
2026-07-29
|
GIMP TIF File Parsing Integer Overflow Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-29404
|
GIMP
|
CVE-2026-18307
|
7.8
|
2026-07-29
|
2026-07-29
|
GIMP TIF File Parsing Heap-based Buffer Overflow
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29396
|
GIMP
|
CVE-2026-18306
|
7.8
|
2026-07-29
|
2026-07-29
|
GIMP SGI File Parsing Integer Overflow Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-29406
|
GIMP
|
CVE-2026-18305
|
7.8
|
2026-07-29
|
2026-07-29
|
GIMP TIF File Parsing Integer Overflow Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-29403
|
GIMP
|
CVE-2026-18304
|
7.8
|
2026-07-29
|
2026-07-29
|
GIMP TIF File Parsing Integer Overflow Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-29399
|
GIMP
|
CVE-2026-18303
|
7.8
|
2026-07-29
|
2026-07-29
|
GIMP TIF File Parsing Stack-based Buffer Overflow
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29398
|
GIMP
|
CVE-2026-18302
|
7.8
|
2026-07-29
|
2026-07-29
|
GIMP TIF File Parsing Heap-based Buffer Overflow
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29395
|
GIMP
|
CVE-2026-18301
|
7.8
|
2026-07-29
|
2026-07-29
|
GIMP PSD File Parsing Integer Overflow Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-29289
|
GIMP
|
CVE-2026-18300
|
7.8
|
2026-07-29
|
2026-07-29
|
GIMP HDR File Parsing Integer Overflow Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-29196
|
LangGenius
|
CVE-2026-18266
|
5.4
|
2026-07-23
|
2026-07-29
|
Dify AI Workflow oauth_redirect_url Open Redirect
Vulnerability
|
||
|
ZDI-CAN-29308
|
Docker
|
|
8.8
|
2026-07-23
|
2026-07-23
|
Docker Desktop for macOS Inference Server
Permissive Allow List Sandbox Escape Vulnerability
|
||
|
ZDI-CAN-28831
|
AzeoTech
|
CVE-2026-12921
|
7.8
|
2026-07-23
|
2026-07-23
|
AzeoTech DAQFactory CTL File Parsing
Use-After-Free Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28876
|
AzeoTech
|
CVE-2026-12390
|
7.8
|
2026-07-23
|
2026-07-23
|
AzeoTech DAQFactory CTL File Parsing Type
Confusion Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28703
|
Bitdefender
|
CVE-2026-6851
|
7.3
|
2026-07-23
|
2026-07-23
|
Bitdefender Total Security Shredder Link
Following Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-29251
|
Heimdall Data
|
CVE-2026-12357
|
7.2
|
2026-07-23
|
2026-07-23
|
Heimdall Data Database Proxy generateFileContent
CRLF Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-32968
|
Microsoft
|
CVE-2026-50297
|
7.0
|
2026-07-21
|
2026-07-21
|
Microsoft Windows WMI Providers Incorrect
Authorization Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-32967
|
Microsoft
|
CVE-2026-50325
|
7.0
|
2026-07-21
|
2026-07-21
|
Microsoft Windows WMI Providers Incorrect
Authorization Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-30169
|
7-Zip
|
CVE-2026-14266
|
7.0
|
2026-07-15
|
2026-07-15
|
7-Zip XZ Decompression Heap-based Buffer Overflow
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-31467
|
Linux
|
|
8.8
|
2026-07-15
|
2026-07-15
|
Linux Kernel vmwgfx Integer Overflow Local
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-31764
|
Linux
|
|
7.8
|
2026-07-15
|
2026-07-15
|
Linux Kernel CAN ISO-TP Protocol Race Condition
Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-29496
|
dnsmasq
|
CVE-2026-2291
|
8.1
|
2026-07-15
|
2026-07-15
|
dnsmasq DNS Response Heap-based Buffer Overflow
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27744
|
Fuji Electric
|
CVE-2026-8108
|
5.5
|
2026-07-15
|
2026-07-15
|
Fuji Electric Tellus pcid64 Driver Untrusted
Pointer Dereference Denial of Service Vulnerability
|
||
|
ZDI-CAN-27670
|
Fuji Electric
|
CVE-2026-8108
|
7.8
|
2026-07-15
|
2026-07-15
|
Fuji Electric Tellus pcid64 Driver Exposed
Dangerous Method Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-27055
|
Rockwell Automation
|
CVE-2026-6071
|
7.8
|
2026-07-15
|
2026-07-15
|
Rockwell Automation Arena Simulation DOE File
Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29113
|
Autel
|
CVE-2026-13308
|
8.1
|
2026-07-15
|
2026-07-15
|
(Pwn2Own) Autel MaxiCharger AC Elite Home
WebSockets Integer Underflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29048
|
Autel
|
CVE-2026-13307
|
6.8
|
2026-07-15
|
2026-07-15
|
(Pwn2Own) Autel MaxiCharger AC Elite Home USB
Heap-based Buffer Overflow Arbitrary Code Execution
Vulnerability
|
||
|
ZDI-CAN-29044
|
Autel
|
CVE-2026-13309
|
6.8
|
2026-07-15
|
2026-07-15
|
(Pwn2Own) Autel MaxiCharger AC Elite Home NFC
Stack-based Buffer Overflow Arbitrary Code Execution
Vulnerability
|
||
|
ZDI-CAN-29046
|
Autel
|
CVE-2026-13306
|
4.3
|
2026-07-15
|
2026-07-15
|
(Pwn2Own) Autel MaxiCharger AC Elite Home USB
Authentication Bypass Vulnerability
|
||
|
ZDI-CAN-29062
|
Autel
|
CVE-2026-13305
|
6.4
|
2026-07-15
|
2026-07-15
|
(Pwn2Own) Autel MaxiCharger AC Elite Home
Software Update Improper Verification of Cryptographic Signature
Arbitrary Code Execution Vulnerability
|
||
|
ZDI-CAN-28665
|
G DATA
|
CVE-2026-13268
|
7.8
|
2026-07-15
|
2026-07-15
|
G DATA Total Security Backup Service Link
Following Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28776
|
ASUS
|
CVE-2026-8921
|
7.8
|
2026-07-15
|
2026-07-15
|
ASUS Business Manager Service Client-Side
Authentication Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28935
|
MSI
|
CVE-2026-6102
|
7.8
|
2026-07-15
|
2026-07-15
|
MSI Center NTIOLib_X64 Origin Validation Error
Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28090
|
NVIDIA
|
CVE-2026-24157
|
7.8
|
2026-07-15
|
2026-07-15
|
NVIDIA NeMo Framework Deserialization of
Untrusted Data Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-30173
|
WatchGuard
|
CVE-2026-8247
|
7.5
|
2026-07-15
|
2026-07-15
|
WatchGuard FireWare OS admd Stack-based Buffer
Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-30097
|
WatchGuard
|
CVE-2026-13084
|
5.9
|
2026-07-15
|
2026-07-15
|
WatchGuard FireWare OS iked ike2_hmac Null
Pointer Dereference Denial-of-Service Vulnerability
|
||
|
ZDI-CAN-30378
|
OpenSSL
|
CVE-2026-42771
|
6.5
|
2026-07-15
|
2026-07-15
|
OpenSSL X.509 Email Validation Out-Of-Bounds Read
Information Disclosure Vulnerability
|
||
|
ZDI-CAN-30391
|
OpenSSL
|
CVE-2026-35188
|
7.5
|
2026-07-15
|
2026-07-15
|
OpenSSL OCSP Stapling Verification Double Free
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28485
|
Synology
|
CVE-2026-13135
|
4.3
|
2026-07-15
|
2026-07-15
|
Synology DiskStation DS925+ MailPlus Improper
Restriction of Communication Channel to Intended Endpoints
Vulnerability
|
||
|
ZDI-CAN-28554
|
Synology
|
CVE-2025-15660
|
8.8
|
2026-07-15
|
2026-07-15
|
Synology DiskStation DS925+ MailPlus Redis Weak
Cryptography for Passwords Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-30236
|
Samsung
|
CVE-2026-15551
|
7.8
|
2026-07-15
|
2026-07-15
|
Samsung rlottie Numeric Truncation Remote Code
Execution Vulnerability
|
||
|
ZDI-CAN-28724
|
Cisco
|
CVE-2026-20146
|
5.5
|
2026-07-15
|
2026-07-15
|
Cisco Identity Services Engine
validFileNameOrPath Directory Traversal Information Disclosure
Vulnerability
|
||
|
ZDI-CAN-29867
|
Adobe
|
CVE-2026-48344
|
7.8
|
2026-07-15
|
2026-07-15
|
Adobe Creative Cloud AGSService Incorrect
Permission Assignment Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-29588
|
Adobe
|
CVE-2026-48272
|
7.0
|
2026-07-15
|
2026-07-15
|
Adobe Creative Cloud AdobeUpdateService
Uncontrolled Search Path Element Local Privilege Escalation
Vulnerability
|
||
|
ZDI-CAN-30803
|
Microsoft
|
CVE-2026-55126
|
7.3
|
2026-07-15
|
2026-07-15
|
Microsoft SharePoint SPFieldMultiLineText
Cross-Site Scripting Vulnerability
|
||
|
ZDI-CAN-30003
|
Microsoft
|
CVE-2026-50311
|
7.8
|
2026-07-15
|
2026-07-15
|
Microsoft Windows ServerManager Exposed Dangerous
Method Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28769
|
Microsoft
|
CVE-2026-54129
|
7.8
|
2026-07-15
|
2026-07-15
|
Microsoft Hyper-V netvsc Out-Of-Bounds Read Local
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-30052
|
Microsoft
|
CVE-2026-49805
|
7.0
|
2026-07-15
|
2026-07-20
|
Microsoft Windows WMI Providers Incorrect
Authorization Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-31478
|
Microsoft
|
CVE-2026-40400
|
7.8
|
2026-07-15
|
2026-07-15
|
Microsoft PowerShell Help Directory Traversal
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-31261
|
Microsoft
|
CVE-2026-50522
|
8.1
|
2026-07-15
|
2026-07-15
|
(Pwn2Own) Microsoft SharePoint Improper
Verification of Cryptographic Signature Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-31490
|
Microsoft
|
CVE-2026-50522
|
8.1
|
2026-07-15
|
2026-07-15
|
(Pwn2Own) Microsoft SharePoint Deserialization of
Untrusted Data Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28693
|
NVIDIA
|
CVE-2026-24237
|
7.8
|
2026-07-15
|
2026-07-15
|
NVIDIA NVTabular Pickle File Parsing
Deserialization of Untrusted Data Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-28677
|
NVIDIA
|
CVE-2026-24228
|
7.8
|
2026-07-15
|
2026-07-15
|
NVIDIA NeMo Framework Deserialization of
Untrusted Data Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-30498
|
X.Org
|
CVE-2026-55999
|
7.8
|
2026-07-15
|
2026-07-15
|
X.Org Server Glamor Font Heap-based Buffer
Overflow Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-30560
|
X.Org
|
CVE-2026-56003
|
7.8
|
2026-07-15
|
2026-07-15
|
X.Org Server ComputeScaledProperties Heap-based
Buffer Overflow Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-30559
|
X.Org
|
CVE-2026-56002
|
7.8
|
2026-07-15
|
2026-07-15
|
X.Org Server PCF Font Parsing Heap-based Buffer
Overflow Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-30558
|
X.Org
|
CVE-2026-56001
|
7.8
|
2026-07-15
|
2026-07-15
|
X.Org Server BitmapScaleBitmaps Integer Overflow
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-30561
|
X.Org
|
CVE-2026-56000
|
7.8
|
2026-07-15
|
2026-07-15
|
X.Org Server GLX Extension Use-After-Free
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-27843
|
Delta Electronics
|
CVE-2026-12578
|
7.8
|
2026-07-15
|
2026-07-15
|
Delta Electronics DTM Soft Project File Parsing
Deserialization of Untrusted Data Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-27277
|
Ollama
|
CVE-2026-15685
|
7.5
|
2026-07-08
|
2026-07-13
|
(0Day) Ollama downloadBlob Improper Validation of
Array Index Denial-of-Service Vulnerability
|
||
|
ZDI-CAN-27004
|
Glarysoft
|
CVE-2026-15684
|
7.3
|
2026-07-08
|
2026-07-13
|
(0Day) Glarysoft Glary Utilities Link Following
Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-26645
|
AnyDesk
|
CVE-2026-15682
|
4.7
|
2026-07-08
|
2026-07-13
|
(0Day) AnyDesk Support Information Link Following
Denial-of-Service Vulnerability
|
||
|
ZDI-CAN-26591
|
AnyDesk
|
CVE-2026-15681
|
4.7
|
2026-07-13
|
2026-07-13
|
(0Day) AnyDesk Screen Recording Link Following
Denial-of-Service Vulnerability
|
||
|
ZDI-CAN-26851
|
Lorex
|
CVE-2026-15683
|
7.5
|
2026-07-08
|
2026-07-13
|
(0Day) (Pwn2Own) Lorex 2K Indoor Wi-Fi Security
Camera Device Management Server Improper Certificate Validation
Vulnerability
|
||
|
ZDI-CAN-25884
|
Lorex
|
CVE-2026-15680
|
7.5
|
2026-07-08
|
2026-07-13
|
(0Day) (Pwn2Own) Lorex 2K Indoor Wi-Fi Security
Camera CDeviceOperator Format String Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-30168
|
X.Org
|
CVE-2026-50263
|
5.5
|
2026-06-24
|
2026-06-24
|
X.Org Server CreateSaverWindow Use-After-Free
Information Disclosure Vulnerability
|
||
|
ZDI-CAN-30165
|
X.Org
|
CVE-2026-50262
|
5.5
|
2026-06-24
|
2026-06-24
|
X.Org Server ChangeDrawableAttributes
Out-Of-Bounds Read Information Disclosure Vulnerability
|
||
|
ZDI-CAN-30164
|
X.Org
|
CVE-2026-50261
|
7.8
|
2026-06-24
|
2026-06-24
|
X.Org Server SyncChangeCounter Use-After-Free
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-30163
|
X.Org
|
CVE-2026-50260
|
7.8
|
2026-06-24
|
2026-06-24
|
X.Org Server FreeCounter Use-After-Free Privilege
Escalation Vulnerability
|
||
|
ZDI-CAN-30161
|
X.Org
|
CVE-2026-50259
|
7.8
|
2026-06-24
|
2026-06-24
|
X.Org Server SetMap Request Stack-based Buffer
Overflow Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-30160
|
X.Org
|
CVE-2026-50258
|
7.8
|
2026-06-24
|
2026-06-24
|
X.Org Server Xkb Key Types Stack-based Buffer
Overflow Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-30159
|
X.Org
|
CVE-2026-50257
|
7.8
|
2026-06-24
|
2026-06-24
|
X.Org Server miSyncDestroyFence Use-After-Free
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-30136
|
X.Org
|
CVE-2026-50256
|
7.8
|
2026-06-24
|
2026-06-24
|
X.Org Server Font Alias Stack-based Buffer
Overflow Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-31818
|
Oracle
|
CVE-2026-35273
|
8.8
|
2026-06-24
|
2026-06-24
|
Oracle PeopleSoft ExecuteProcessActivityCommand
External Control of File Path Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-31817
|
Oracle
|
CVE-2026-35273
|
7.5
|
2026-06-24
|
2026-06-24
|
Oracle PeopleSoft HubMBeanPersistance
Deserialization of Untrusted Data Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-31816
|
Oracle
|
CVE-2026-35273
|
9.3
|
2026-06-24
|
2026-06-24
|
Oracle PeopleSoft HttpListeningConnector
Server-Side Request Forgery Vulnerability
|
||
|
ZDI-CAN-30134
|
Unraid
|
CVE-2026-9773
|
8.8
|
2026-06-24
|
2026-06-24
|
Unraid Web Server ToggleState Command Injection
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-30116
|
Unraid
|
CVE-2026-9772
|
8.8
|
2026-06-24
|
2026-06-24
|
Unraid Web Server FileUpload Command Injection
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27990
|
MosaicML
|
CVE-2026-10043
|
7.8
|
2026-06-24
|
2026-06-24
|
MosaicML Composer Deserialization of Untrusted
Data Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28590
|
ATEN
|
CVE-2026-9779
|
7.2
|
2026-06-24
|
2026-06-24
|
ATEN Unizon doCryptoHugeFileToFile Improper
Verification of Cryptographic Signature Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-28579
|
ATEN
|
CVE-2026-9778
|
7.2
|
2026-06-24
|
2026-06-24
|
ATEN Unizon ImportDeviceList Directory Traversal
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28578
|
ATEN
|
CVE-2026-9777
|
7.2
|
2026-06-24
|
2026-06-24
|
ATEN Unizon restoreDB Directory Traversal Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-28505
|
ATEN
|
CVE-2026-9776
|
7.5
|
2026-06-24
|
2026-06-24
|
ATEN Unizon writeFileToHttpServletResponse
Directory Traversal Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28503
|
ATEN
|
CVE-2026-9775
|
5.5
|
2026-06-24
|
2026-06-24
|
ATEN Unizon uploadSSL Directory Traversal
Arbitrary File Deletion Vulnerability
|
||
|
ZDI-CAN-28502
|
ATEN
|
CVE-2026-9774
|
5.5
|
2026-06-24
|
2026-06-24
|
ATEN Unizon updateLicense Directory Traversal
Arbitrary File Deletion Vulnerability
|
||
|
ZDI-CAN-28202
|
Quest
|
CVE-2026-7569
|
8.8
|
2026-06-24
|
2026-06-24
|
Quest NetVault Backup viewclient Cross-Site
Scripting Authentication Bypass Vulnerability
|
||
|
ZDI-CAN-27625
|
Quest
|
CVE-2026-9787
|
8.8
|
2026-06-24
|
2026-06-24
|
Quest NetVault Backup NVBULogDaemon Command
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27626
|
Quest
|
CVE-2026-9786
|
8.8
|
2026-06-24
|
2026-06-24
|
Quest NetVault Backup NVBUDashboard SQL Injection
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27630
|
Quest
|
CVE-2026-9785
|
8.8
|
2026-06-24
|
2026-06-24
|
Quest NetVault Backup NVBULibrarySlot SQL
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27631
|
Quest
|
CVE-2026-9784
|
8.8
|
2026-06-24
|
2026-06-24
|
Quest NetVault Backup NVBULibraryPort SQL
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27632
|
Quest
|
CVE-2026-9783
|
8.8
|
2026-06-24
|
2026-06-24
|
Quest NetVault Backup NVBURemovableMedia SQL
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27633
|
Quest
|
CVE-2026-9782
|
8.8
|
2026-06-24
|
2026-06-24
|
Quest NetVault Backup NVBUDeviceDrive SQL
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27648
|
Quest
|
CVE-2026-9781
|
8.8
|
2026-06-24
|
2026-06-24
|
Quest NetVault Backup NVBURASDevice SQL Injection
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27666
|
Quest
|
CVE-2026-9780
|
8.8
|
2026-06-24
|
2026-06-24
|
Quest NetVault Backup addclient3 Cross-Site
Scripting Authentication Bypass Vulnerability
|
||
|
ZDI-CAN-27809
|
Quest
|
CVE-2026-7570
|
8.8
|
2026-06-24
|
2026-06-24
|
Quest NetVault Backup NVBUDashboard SQL Injection
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27671
|
Fuji Electric
|
CVE-2026-8108
|
7.8
|
2026-06-24
|
2026-06-24
|
Fuji Electric Tellus pcid64 Driver Registry APIs
Exposed Dangerous Method Local Privilege Escalation
Vulnerability
|
||
|
ZDI-CAN-27673
|
Fuji Electric
|
CVE-2026-8108
|
7.8
|
2026-06-24
|
2026-06-24
|
Fuji Electric Tellus pcid64 Driver File APIs
Exposed Dangerous Method Arbitrary File Deletion Vulnerability
|
||
|
ZDI-CAN-29410
|
Flowise
|
CVE-2026-41137
|
8.8
|
2026-06-24
|
2026-06-24
|
FlowiseAI Flowise CSV Agent customReadCSV Code
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29411
|
Flowise
|
CVE-2026-41264
|
9.8
|
2026-06-24
|
2026-06-24
|
FlowiseAI Flowise CSV Agent Prompt Injection
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29539
|
Docker
|
CVE-2026-55887
|
8.6
|
2026-06-24
|
2026-06-24
|
Docker MCP Plugin OCI Image Label Parsing
Argument Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29271
|
Oracle
|
CVE-2026-46873
|
7.5
|
2026-06-24
|
2026-06-24
|
Oracle VirtualBox VMSVGA Stack-based Buffer
Overflow Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-29178
|
Adobe
|
CVE-2026-27278
|
7.8
|
2026-06-24
|
2026-06-24
|
Adobe Acrobat Reader DC Field signatureInfo
Use-After-Free Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-30289
|
MATE Desktop
|
CVE-2026-52849
|
7.8
|
2026-06-11
|
2026-06-11
|
MATE Desktop Atril Document Viewer EPUB File
Parsing Heap-based Buffer Overflow Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-30288
|
Samsung
|
CVE-2026-8916
|
7.8
|
2026-06-11
|
2026-06-11
|
Samsung rlottie Numeric Truncation Remote Code
Execution Vulnerability
|
||
|
ZDI-CAN-28236
|
Allegra
|
CVE-2026-11443
|
4.6
|
2026-06-11
|
2026-06-11
|
Allegra downloadAttachment Cross-Site Scripting
Authentication Bypass Vulnerability
|
||
|
ZDI-CAN-28208
|
Allegra
|
CVE-2026-11442
|
6.5
|
2026-06-11
|
2026-06-11
|
Allegra exportReport Directory Traversal
Information Disclosure Vulnerability
|
||
|
ZDI-CAN-30089
|
Apache
|
CVE-2026-34032
|
3.7
|
2026-06-11
|
2026-06-11
|
Apache HTTP Server mod_proxy_ajp Out-Of-Bounds
Read Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28816
|
Adobe
|
CVE-2026-27220
|
7.8
|
2026-06-10
|
2026-06-10
|
Adobe Acrobat Reader DC Annotation Use-After-Free
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29987
|
Adobe
|
CVE-2026-47919
|
7.8
|
2026-06-09
|
2026-06-09
|
Adobe Acrobat Reader DC Annotation Use-After-Free
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-30387
|
Adobe
|
CVE-2026-47918
|
7.8
|
2026-06-09
|
2026-06-09
|
Adobe Acrobat Reader DC Annotation Use-After-Free
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-30689
|
Adobe
|
CVE-2026-47917
|
7.8
|
2026-06-09
|
2026-06-09
|
Adobe Acrobat Pro DC AcroForm Use-After-Free
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-30375
|
Adobe
|
CVE-2026-48292
|
7.8
|
2026-06-09
|
2026-06-09
|
Adobe USD-Fileformat-plugins Heap-based Buffer
Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29653
|
Adobe
|
CVE-2026-48291
|
7.8
|
2026-06-09
|
2026-06-09
|
Adobe USD-Fileformat-plugins Heap-based Buffer
Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29886
|
Adobe
|
CVE-2026-47915
|
7.8
|
2026-06-09
|
2026-06-09
|
Adobe Acrobat Pro DC Annots.api Use-After-Free
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29896
|
Adobe
|
CVE-2026-47914
|
7.8
|
2026-06-09
|
2026-06-09
|
Adobe Acrobat Reader DC Annotation Use-After-Free
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29409
|
Adobe
|
CVE-2026-47913
|
7.8
|
2026-06-09
|
2026-06-09
|
Adobe Acrobat Reader DC Multimedia Rendition
Use-After-Free Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29433
|
Adobe
|
CVE-2026-47924
|
3.3
|
2026-06-09
|
2026-06-09
|
Adobe Acrobat Reader DC Annotation Use-After-Free
Information Disclosure Vulnerability
|
||
|
ZDI-CAN-30015
|
Adobe
|
CVE-2026-47912
|
7.8
|
2026-06-09
|
2026-06-09
|
Adobe Acrobat Reader DC Font Handling
Use-After-Free Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29477
|
Adobe
|
CVE-2026-47923
|
3.3
|
2026-06-09
|
2026-06-09
|
Adobe Acrobat Reader DC Doc Object Out-Of-Bounds
Read Information Disclosure Vulnerability
|
||
|
ZDI-CAN-29828
|
Adobe
|
CVE-2026-47911
|
7.8
|
2026-06-09
|
2026-06-09
|
Adobe Acrobat Reader DC TIF File Parsing Integer
Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-30437
|
Progress Software
|
CVE-2026-8037
|
9.8
|
2026-06-09
|
2026-06-09
|
Progress Software Kemp LoadMaster apiuser
Uninitialized Memory Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-30439
|
Progress Software
|
CVE-2026-8037
|
7.2
|
2026-06-09
|
2026-06-09
|
Progress Software Kemp LoadMaster dolistapikeys
Uninitialized Memory Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-30438
|
Progress Software
|
CVE-2026-8037
|
8.8
|
2026-06-09
|
2026-06-09
|
Progress Software Kemp LoadMaster dodelapikey
Uninitialized Memory Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28792
|
Microsoft
|
CVE-2026-48565
|
7.0
|
2026-06-09
|
2026-06-09
|
Microsoft Windows Narrator Braille Support brlapi
Exposed Dangerous Function Local Privilege Escalation
Vulnerability
|
||
|
ZDI-CAN-28649
|
NVIDIA
|
CVE-2026-24162
|
7.8
|
2026-06-09
|
2026-06-09
|
NVIDIA Transformers4Rec Model.load
Deserialization of Untrusted Data Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-28736
|
X.Org
|
CVE-2026-34003
|
7.8
|
2026-06-09
|
2026-06-09
|
X.Org Server CheckKeyTypes Buffer Overflow
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28737
|
X.Org
|
CVE-2026-34002
|
6.1
|
2026-06-09
|
2026-06-09
|
X.Org Server CheckKeyActions Out-Of-Bounds Read
Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28706
|
X.Org
|
CVE-2026-34001
|
7.8
|
2026-06-09
|
2026-06-09
|
X.Org Server SyncAwaitFence Use-After-Free
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28679
|
X.Org
|
CVE-2026-34000
|
6.1
|
2026-06-09
|
2026-06-09
|
X.Org Server CheckSetGeom Out-Of-Bounds Read
Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28593
|
X.Org
|
CVE-2026-33999
|
7.8
|
2026-06-09
|
2026-06-09
|
X.Org Server XkbSetCompatMap Integer Underflow
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-27578
|
QEMU
|
CVE-2026-3886
|
8.8
|
2026-06-09
|
2026-06-09
|
QEMU calc_image_hostmem Integer Overflow Local
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-31431
|
Microsoft
|
CVE-2026-45495
|
7.5
|
2026-06-04
|
2026-06-04
|
(Pwn2Own) Microsoft Edge Feedback Log File
Handling Directory Traversal Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-31430
|
Microsoft
|
CVE-2026-45494
|
5.0
|
2026-06-04
|
2026-06-04
|
(Pwn2Own) Microsoft Edge Navigation Handling
Universal Cross-Site Scripting Vulnerability
|
||
|
ZDI-CAN-31429
|
Microsoft
|
CVE-2026-45492
|
4.3
|
2026-06-04
|
2026-06-04
|
(Pwn2Own) Microsoft Edge Origin Validation Error
Security Bypass Vulnerability
|
||
|
ZDI-CAN-28489
|
ASUS
|
CVE-2026-7480
|
7.8
|
2026-06-10
|
2026-06-10
|
ASUS MyASUS Origin Validation Error Local
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-30796
|
Docker
|
CVE-2026-8936
|
6.5
|
2026-06-03
|
2026-06-03
|
Docker Desktop grpcfuse Kernel Module
Uncontrolled Recursion Denial-of-Service Vulnerability
|
||
|
ZDI-CAN-27982
|
TrendAI
|
CVE-2026-45208
|
7.8
|
2026-05-28
|
2026-05-29
|
TrendAI Vision One Security Agent Time-Of-Check
Time-Of-Use Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-29177
|
TrendAI
|
CVE-2026-45207
|
7.8
|
2026-05-28
|
2026-05-29
|
TrendAI Vision One Security Agent Origin
Validation Error Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28118
|
TrendAI
|
CVE-2026-45206
|
7.8
|
2026-05-28
|
2026-05-29
|
TrendAI Vision One Security Agent Origin
Validation Error Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28089
|
TrendAI
|
CVE-2026-34930
|
7.8
|
2026-05-28
|
2026-05-29
|
TrendAI Vision One Security Agent Origin
Validation Error Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28077
|
TrendAI
|
CVE-2026-34929
|
7.8
|
2026-05-28
|
2026-05-29
|
TrendAI Vision One Security Agent Origin
Validation Error Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28061
|
TrendAI
|
CVE-2026-34928
|
7.8
|
2026-05-28
|
2026-05-29
|
TrendAI Vision One Security Agent Origin
Validation Error Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-27959
|
TrendAI
|
CVE-2026-34927
|
7.8
|
2026-05-28
|
2026-05-29
|
TrendAI Vision One Security Agent Origin
Validation Error Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-29249
|
Progress Software
|
CVE-2026-3517
|
8.8
|
2026-05-21
|
2026-05-21
|
Progress Software Kemp LoadMaster addcountry
Command Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29222
|
Progress Software
|
CVE-2026-3518
|
8.8
|
2026-05-21
|
2026-05-21
|
Progress Software Kemp LoadMaster
ssodomain_killsession Command Injection Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-27349
|
Siemens
|
CVE-2025-12659
|
7.8
|
2026-05-12
|
2026-05-15
|
Siemens Simcenter Femap IPT File Parsing Memory
Corruption Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27389
|
Siemens
|
CVE-2025-12659
|
7.8
|
2026-05-12
|
2026-05-15
|
Siemens Simcenter Femap IPT File Parsing Memory
Corruption Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29240
|
Apple
|
CVE-2026-28941
|
3.3
|
2026-05-12
|
2026-05-12
|
Apple macOS USD Out-Of-Bounds Read Information
Disclosure Vulnerability
|
||
|
ZDI-CAN-29239
|
Apple
|
CVE-2026-28940
|
7.8
|
2026-05-12
|
2026-05-12
|
Apple macOS USD File Parsing Out-Of-Bounds Write
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29186
|
Apple
|
CVE-2026-28847
|
8.8
|
2026-05-12
|
2026-05-12
|
Apple Safari Regular Expression Duplicate Named
Groups Heap-based Buffer Overflow Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-28879
|
Apple
|
CVE-2026-28955
|
7.5
|
2026-05-12
|
2026-05-12
|
Apple Safari Web Inspector WebCore Style Resolver
Use-After-Free Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28695
|
Apple
|
CVE-2026-28918
|
3.3
|
2026-05-12
|
2026-05-12
|
Apple macOS CoreSymbolication Out-Of-Bounds Read
Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28605
|
Microsoft
|
CVE-2026-34342
|
4.4
|
2026-05-12
|
2026-05-12
|
Microsoft Windows splwow64 Race Condition Local
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28559
|
Microsoft
|
CVE-2026-33838
|
7.8
|
2026-05-12
|
2026-05-12
|
Microsoft Windows Message Queueing Double Free
Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28617
|
Ivanti
|
CVE-2026-8109
|
4.9
|
2026-05-12
|
2026-05-12
|
Ivanti Endpoint Manager RemoteControlAuth Exposed
Dangerous Method Information Disclosure Vulnerability
|
||
|
ZDI-CAN-29412
|
Flowise
|
CVE-2026-41265
|
9.8
|
2026-05-01
|
2026-05-01
|
FlowiseAI Flowise Airtable_Agent Code Injection
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28806
|
Oracle
|
CVE-2026-35230
|
7.5
|
2026-04-28
|
2026-04-28
|
Oracle VirtualBox SoundBlaster 16 Race Condition
Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-29475
|
OpenAI
|
|
8.6
|
2026-04-28
|
2026-04-28
|
(0Day) OpenAI Codex Sandbox Escape Vulnerability
|
||
|
ZDI-CAN-29495
|
Foxit
|
CVE-2026-5943
|
7.8
|
2026-04-27
|
2026-04-27
|
Foxit PDF Reader AcroForm Annotation
Use-After-Free Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29494
|
Foxit
|
CVE-2026-5942
|
3.3
|
2026-04-27
|
2026-04-27
|
Foxit PDF Reader AcroForm Signature
Use-After-Free Information Disclosure Vulnerability
|
||
|
ZDI-CAN-29492
|
Foxit
|
CVE-2026-5941
|
7.8
|
2026-04-27
|
2026-04-27
|
Foxit PDF Reader AcroForm Signature
Use-After-Free Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29491
|
Foxit
|
CVE-2026-5940
|
7.8
|
2026-04-27
|
2026-04-27
|
Foxit PDF Reader Annotation Use-After-Free Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-28762
|
Flowise
|
CVE-2026-41276
|
8.1
|
2026-04-27
|
2026-04-27
|
Flowise AccountService resetPassword
Authentication Bypass Vulnerability
|
||
|
ZDI-CAN-28822
|
Docker
|
CVE-2026-6406
|
8.8
|
2026-04-23
|
2026-04-23
|
Docker Desktop Enhanced Container Isolation
Exposed Dangerous Function Local Privilege Escalation
Vulnerability
|
||
|
ZDI-CAN-27564
|
Siemens
|
CVE-2026-24032
|
7.3
|
2026-04-23
|
2026-04-23
|
Siemens SINEC NMS Authentication Bypass
Vulnerability
|
||
|
ZDI-CAN-28759
|
Siemens
|
CVE-2026-25654
|
8.8
|
2026-04-23
|
2026-04-23
|
Siemens SINEC NMS Improper Authentication
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28692
|
Delta Electronics
|
CVE-2026-5726
|
7.8
|
2026-04-23
|
2026-04-23
|
Delta Electronics ASDA-Soft PAR File Parsing
Stack-based Buffer Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-23734
|
PublicCMS
|
|
8.2
|
2026-04-21
|
2026-04-21
|
(0Day) PublicCMS getXml Server-Side Request
Forgery Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28157
|
Microsoft
|
|
3.5
|
2026-04-21
|
2026-04-21
|
(0Day) Microsoft Windows library-ms NTLM Response
Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28651
|
Microsoft
|
|
4.3
|
2026-04-21
|
2026-04-21
|
(0Day) Microsoft Office URI Handler NTLM Response
Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28327
|
QNAP
|
CVE-2026-22898
|
8.8
|
2026-04-15
|
2026-04-15
|
QNAP TS-453E QVRPro excpostgres Exposed Dangerous
Method Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28516
|
NI
|
CVE-2026-32861
|
7.8
|
2026-04-15
|
2026-04-15
|
NI LabVIEW LVCLASS File Parsing Memory Corruption
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28463
|
NI
|
CVE-2026-32860
|
7.8
|
2026-04-15
|
2026-04-15
|
NI LabVIEW LVLIB File Parsing Memory Corruption
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28490
|
Linux
|
CVE-2025-71066
|
7.5
|
2026-04-15
|
2026-04-15
|
Linux Kernel ETS Scheduler Race Condition Local
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28713
|
DriveLock
|
CVE-2026-5492
|
6.5
|
2026-04-15
|
2026-04-15
|
DriveLock Directory Traversal Information
Disclosure Vulnerability
|
||
|
ZDI-CAN-28722
|
DriveLock
|
CVE-2026-5491
|
7.5
|
2026-04-15
|
2026-04-15
|
DriveLock Directory Traversal Information
Disclosure Vulnerability
|
||
|
ZDI-CAN-28726
|
DriveLock
|
CVE-2026-5490
|
8.8
|
2026-04-15
|
2026-04-15
|
DriveLock SQL Injection Privilege Escalation
Vulnerability
|
||
|
ZDI-CAN-28719
|
DriveLock
|
CVE-2026-5489
|
5.3
|
2026-04-15
|
2026-04-15
|
DriveLock Directory Traversal Information
Disclosure Vulnerability
|
||
|
ZDI-CAN-28746
|
DriveLock
|
CVE-2026-5487
|
7.5
|
2026-04-15
|
2026-04-15
|
DriveLock Directory Traversal Information
Disclosure Vulnerability
|
||
|
ZDI-CAN-29392
|
GStreamer
|
CVE-2026-5056
|
7.8
|
2026-04-15
|
2026-04-15
|
GStreamer qtdemux Stack-based Buffer Overflow
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28266
|
GIMP
|
CVE-2026-2050
|
7.8
|
2026-04-15
|
2026-04-15
|
GIMP HDR File Parsing Heap-based Buffer Overflow
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29616
|
Microsoft
|
CVE-2026-34054
|
7.8
|
2026-04-15
|
2026-04-15
|
Microsoft vcpkg OpenSSL Uncontrolled Search Path
Element Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28366
|
HP
|
CVE-2026-4682
|
8.8
|
2026-04-15
|
2026-04-15
|
(Pwn2Own) HP DeskJet 2855e JobStatusEvent
Stack-based Buffer Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28793
|
Microsoft
|
CVE-2026-32183
|
7.5
|
2026-04-15
|
2026-04-15
|
Microsoft Windows Snipping Tool Improper Input
Validation Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28267
|
Microsoft
|
CVE-2026-33104
|
7.8
|
2026-04-15
|
2026-04-15
|
Microsoft Windows win32kfull Improper Locking
Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28540
|
Microsoft
|
CVE-2026-32073
|
7.8
|
2026-04-15
|
2026-04-15
|
Microsoft Windows afd.sys Race Condition Local
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28189
|
Microsoft
|
CVE-2026-26179
|
7.5
|
2026-04-15
|
2026-04-15
|
Microsoft Windows Secure Kernel Double Free Local
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-27212
|
Microsoft
|
|
8.8
|
2026-04-15
|
2026-04-15
|
Microsoft Qlib _mount_nfs_uri Command Injection
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27211
|
Microsoft
|
|
7.8
|
2026-04-15
|
2026-04-15
|
Microsoft Qlib fit Deserialization of Untrusted
Data Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28054
|
Microsoft
|
|
7.8
|
2026-04-15
|
2026-04-15
|
Microsoft Olive Deserialization of Untrusted Data
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29041
|
ATEN
|
CVE-2026-5057
|
7.5
|
2026-04-15
|
2026-04-15
|
ATEN Unizon RpcProvider Missing Authentication
Denial-of-Service Vulnerability
|
||
|
ZDI-CAN-29388
|
Avast
|
CVE-2026-5424
|
7.8
|
2026-04-15
|
2026-04-15
|
Avast Premium Security Gen Self Protection Driver
Exposed Dangerous Function Local Privilege Escalation
Vulnerability
|
||
|
ZDI-CAN-27976
|
TrendAI
|
CVE-2025-54987
|
9.8
|
2026-04-15
|
2026-04-15
|
TrendAI Apex One Console Directory Traversal
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27975
|
TrendAI
|
CVE-2025-54948
|
9.8
|
2026-04-15
|
2026-04-15
|
TrendAI Apex One Console Directory Traversal
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28705
|
Samsung
|
CVE-2026-25203
|
7.8
|
2026-04-15
|
2026-04-15
|
Samsung MagicINFO 9 Server Incorrect Default
Permissions Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-22936
|
Malwarebytes
|
|
7.8
|
2026-04-15
|
2026-04-15
|
Malwarebytes Anti-Malware Uncontrolled Search
Path Element Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28661
|
Fortinet
|
CVE-2026-40688
|
8.8
|
2026-04-15
|
2026-04-15
|
Fortinet FortiWeb cat_cgi_paths Out-Of-Bounds
Write Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28660
|
Fortinet
|
CVE-2026-39811
|
6.5
|
2026-04-15
|
2026-04-15
|
Fortinet FortiWeb cgi_buf_alloc Integer Overflow
Denial-of-Service Vulnerability
|
||
|
ZDI-CAN-29550
|
Adobe
|
CVE-2026-27305
|
7.5
|
2026-04-15
|
2026-04-15
|
Adobe ColdFusion fetchCFSettingFile Directory
Traversal Information Disclosure Vulnerability
|
||
|
ZDI-CAN-30200
|
Adobe
|
CVE-2026-27282
|
6.5
|
2026-04-15
|
2026-04-15
|
Adobe ColdFusion subscribeToEndpoints
Authentication Bypass Vulnerability
|
||
|
ZDI-CAN-29549
|
Adobe
|
CVE-2026-34619
|
5.4
|
2026-04-15
|
2026-04-15
|
Adobe ColdFusion deleteVersion Directory
Traversal Arbitrary File Deletion Vulnerability
|
||
|
ZDI-CAN-27431
|
Docker
|
|
7.5
|
2026-04-15
|
2026-04-21
|
(0Day) Docker Desktop credentialHelper Directory
Traversal Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-27571
|
Docker
|
|
7.5
|
2026-04-15
|
2026-04-21
|
(0Day) Docker Desktop System Editor Uncontrolled
Search Path Element Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-27430
|
Docker
|
|
7.8
|
2026-04-15
|
2026-04-21
|
(0Day) Docker Desktop cli-plugins Incorrect
Permission Assignment Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-27229
|
Docker
|
|
8.2
|
2026-04-15
|
2026-04-21
|
(0Day) Docker Desktop extension-manager Exposed
Dangerous Function Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-25720
|
Labcenter Electronics
|
CVE-2026-5495
|
7.8
|
2026-04-06
|
2026-04-21
|
(0Day) Labcenter Electronics Proteus PDSPRJ File
Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-25719
|
Labcenter Electronics
|
CVE-2026-5494
|
7.8
|
2026-04-06
|
2026-04-21
|
(0Day) Labcenter Electronics Proteus PDSPRJ File
Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-25718
|
Labcenter Electronics
|
CVE-2026-5493
|
7.8
|
2026-04-06
|
2026-04-21
|
(0Day) Labcenter Electronics Proteus PDSPRJ File
Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-25717
|
Labcenter Electronics
|
CVE-2026-5496
|
7.8
|
2026-04-06
|
2026-04-21
|
(0Day) Labcenter Electronics Proteus PDSPRJ File
Parsing Type Confusion Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29184
|
Microsoft
|
CVE-2026-21518
|
7.8
|
2026-04-02
|
2026-04-02
|
Microsoft Visual Studio Code mcp.json Command
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29301
|
Mozilla
|
CVE-2026-4698
|
8.8
|
2026-04-02
|
2026-04-02
|
Mozilla Firefox IonMonkey Switch Statement
Optimization Type Confusion Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28595
|
Foxit
|
CVE-2026-3775
|
7.8
|
2026-04-02
|
2026-04-02
|
Foxit PDF Reader Update Service Uncontrolled
Search Path Element Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28893
|
Linux
|
CVE-2026-23092
|
8.2
|
2026-03-31
|
2026-03-31
|
Linux Kernel Analog Device Driver Improper
Validation of Array Index Local Privilege Escalation
Vulnerability
|
||
|
ZDI-CAN-28494
|
NoMachine
|
CVE-2026-5055
|
7.8
|
2026-03-30
|
2026-03-30
|
NoMachine Uncontrolled Search Path Element Local
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28630
|
NoMachine
|
CVE-2026-5054
|
7.8
|
2026-03-30
|
2026-03-30
|
NoMachine External Control of File Path Local
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28644
|
NoMachine
|
CVE-2026-5053
|
7.1
|
2026-03-30
|
2026-03-30
|
NoMachine External Control of File Path Arbitrary
File Deletion Vulnerability
|
||
|
ZDI-CAN-27968
|
aws-mcp-server
|
CVE-2026-5058
|
9.8
|
2026-03-30
|
2026-04-21
|
(0Day) aws-mcp-server Command Injection Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-27969
|
aws-mcp-server
|
CVE-2026-5059
|
9.8
|
2026-04-21
|
2026-04-21
|
(0Day) aws-mcp-server AWS CLI Command Injection
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-25846
|
QNAP
|
CVE-2024-13088
|
5.0
|
2026-03-30
|
2026-03-30
|
(Pwn2Own) QNAP QHora-322
miro_webserver_controllers_api_login_singIn Authentication
Bypass Vulnerability
|
||
|
ZDI-CAN-28428
|
QNAP
|
CVE-2025-62842
|
6.8
|
2026-03-30
|
2026-03-30
|
(Pwn2Own) QNAP TS-453E write_file_to_svr External
Control of File Path Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28426
|
QNAP
|
CVE-2025-62840
|
3.5
|
2026-03-30
|
2026-03-30
|
(Pwn2Own) QNAP TS-453E server_handlers.pyc
rr2s.kwargs Error Message Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28424
|
QNAP
|
CVE-2025-62846
|
8.8
|
2026-03-30
|
2026-03-30
|
(Pwn2Own) QNAP QHora-322 qvpn_db_mgr username SQL
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28423
|
QNAP
|
CVE-2025-62845
|
6.3
|
2026-03-30
|
2026-03-30
|
(Pwn2Own) QNAP QHora-322 qvpn_db_mgr role_type
Improper Neutralization of Escape Sequences Authentication
Bypass Vulnerability
|
||
|
ZDI-CAN-28422
|
QNAP
|
CVE-2025-62844
|
5.6
|
2026-03-30
|
2026-03-30
|
(Pwn2Own) QNAP QHora-322
login.newAuthMiddleware.Authenticator Authentication Bypass
Vulnerability
|
||
|
ZDI-CAN-22236
|
Linux
|
CVE-2023-6270
|
7.8
|
2026-03-30
|
2026-03-30
|
Linux Kernel AoE Driver Use-After-Free Local
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28371
|
QNAP
|
CVE-2025-62843
|
6.3
|
2026-03-30
|
2026-03-30
|
(Pwn2Own) QNAP QHora-322 ip6_wanifset Improper
Restriction of Communication Channel to Intended Endpoints
Firewall Bypass Vulnerability
|
||
|
ZDI-CAN-28152
|
Digilent
|
CVE-2026-0954
|
7.8
|
2026-03-30
|
2026-03-30
|
Digilent DASYLab DSB File Parsing Out-Of-Bounds
Write Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28446
|
Digilent
|
CVE-2026-0957
|
7.8
|
2026-03-30
|
2026-03-30
|
Digilent DASYLab DSA File Parsing Out-Of-Bounds
Write Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28445
|
Digilent
|
CVE-2026-0956
|
7.8
|
2026-03-30
|
2026-03-30
|
Digilent DASYLab DSA File Parsing Out-Of-Bounds
Read Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28444
|
Digilent
|
CVE-2026-0955
|
7.8
|
2026-03-30
|
2026-03-30
|
Digilent DASYLab DSA File Parsing Out-Of-Bounds
Read Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27173
|
Red Hat
|
CVE-2025-40277
|
8.8
|
2026-03-30
|
2026-03-30
|
(Pwn2Own) Red Hat Enterprise Linux vmwgfx Driver
Integer Overflow Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28499
|
Apple
|
CVE-2026-20695
|
3.8
|
2026-03-30
|
2026-03-30
|
Apple macOS Exposure of Sensitive Information to
Unauthorized Sphere Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28894
|
Apple
|
CVE-2026-20690
|
8.8
|
2026-03-30
|
2026-03-30
|
Apple macOS CoreMedia Framework Out-Of-Bounds
Write Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-29381
|
OpenClaw
|
CVE-2026-3691
|
5.3
|
2026-03-30
|
2026-03-30
|
OpenClaw Client PKCE Verifier Information
Disclosure Vulnerability
|
||
|
ZDI-CAN-29311
|
OpenClaw
|
CVE-2026-3690
|
7.4
|
2026-03-30
|
2026-03-30
|
OpenClaw Canvas Authentication Bypass
Vulnerability
|
||
|
ZDI-CAN-29312
|
OpenClaw
|
CVE-2026-3689
|
6.5
|
2026-03-30
|
2026-03-30
|
OpenClaw Canvas Path Traversal Information
Disclosure Vulnerability
|
||
|
ZDI-CAN-28042
|
Microsoft
|
|
9.8
|
2026-03-24
|
2026-04-21
|
(0Day) Microsoft Azure MCP AzureCliService
Command Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28457
|
Samsung
|
CVE-2025-58487
|
5.6
|
2026-03-23
|
2026-03-23
|
(Pwn2Own) Samsung Galaxy S25 Samsung Account Open
Redirect Security Bypass Vulnerability
|
||
|
ZDI-CAN-28456
|
Samsung
|
CVE-2025-58486
|
6.3
|
2026-03-23
|
2026-03-23
|
(Pwn2Own) Samsung Galaxy S25 Samsung Account
Cross-Site Scripting Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28331
|
Samsung
|
CVE-2025-58488
|
5.9
|
2026-03-23
|
2026-03-23
|
(Pwn2Own) Samsung Galaxy S25 Smart Touch Call
Application Protection Mechanism Failure Information Disclosure
Vulnerability
|
||
|
ZDI-CAN-28369
|
Canon
|
CVE-2025-14233
|
8.8
|
2026-03-23
|
2026-03-23
|
(Pwn2Own) Canon imageCLASS MF654Cdw BJNP Memory
Corruption Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28901
|
GIMP
|
CVE-2026-4154
|
7.8
|
2026-03-19
|
2026-03-19
|
GIMP XPM File Parsing Integer Overflow Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-28874
|
GIMP
|
CVE-2026-4153
|
7.8
|
2026-03-19
|
2026-03-19
|
GIMP PSP File Parsing Heap-based Buffer Overflow
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28863
|
GIMP
|
CVE-2026-4152
|
7.8
|
2026-03-19
|
2026-03-19
|
GIMP JP2 File Parsing Heap-based Buffer Overflow
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28813
|
GIMP
|
CVE-2026-4151
|
7.8
|
2026-03-19
|
2026-03-19
|
GIMP ANI File Parsing Integer Overflow Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-28807
|
GIMP
|
CVE-2026-4150
|
7.8
|
2026-03-19
|
2026-03-19
|
GIMP PSD File Parsing Integer Overflow Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-28353
|
QNAP
|
CVE-2025-62847
|
6.3
|
2026-03-17
|
2026-03-17
|
(Pwn2Own) QNAP TS-453E smbd domain_name Argument
Injection Authentication Bypass Vulnerability
|
||
|
ZDI-CAN-29156
|
KeePassXC
|
CVE-2026-4158
|
7.3
|
2026-03-16
|
2026-03-16
|
KeePassXC OpenSSL Configuration Uncontrolled
Search Path Element Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28618
|
GIMP
|
CVE-2026-2049
|
7.8
|
2026-03-16
|
2026-03-16
|
GIMP HDR File Parsing Heap-based Buffer Overflow
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28405
|
GIMP
|
CVE-2026-2046
|
7.8
|
2026-03-16
|
2026-03-16
|
GIMP LBM File Parsing Heap-based Buffer Overflow
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28034
|
Schneider Electric
|
CVE-2025-13957
|
8.8
|
2026-03-16
|
2026-03-16
|
Schneider Electric EcoStruxure Data Center Expert
Hard-coded Password Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28685
|
Delta Electronics
|
CVE-2026-1361
|
7.8
|
2026-03-16
|
2026-03-16
|
Delta Electronics ASDA-Soft PAR File Parsing
Stack-based Buffer Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28233
|
Samsung
|
CVE-2025-21079
|
5.4
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) Samsung Galaxy S25 Samsung Members
Security Feature Bypass Vulnerability
|
||
|
ZDI-CAN-28455
|
Samsung
|
CVE-2025-21079
|
5.0
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) Samsung Galaxy S25 Samsung Members Open
Redirect Security Bypass Vulnerability
|
||
|
ZDI-CAN-28363
|
Canon
|
CVE-2025-14237
|
8.8
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) Canon imageCLASS MF654Cdw TTF Parsing
Integer Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28373
|
Canon
|
CVE-2025-14236
|
8.8
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) Canon imageCLASS MF654Cdw
dtdc_addr_importSub Stack-based Buffer Overflow Remote Code
Execution Vulnerability
|
||
|
ZDI-CAN-28349
|
Canon
|
CVE-2025-14235
|
8.8
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) Canon imageCLASS MF654Cdw TTF Parsing
Out-Of-Bounds Write Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28334
|
Canon
|
CVE-2025-14234
|
8.8
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) Canon imageCLASS MF654Cdw PJCC Request
Parsing Heap-based Buffer Overflow Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-28268
|
Canon
|
CVE-2025-14232
|
8.8
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) Canon imageCLASS MF654Cdw XPS Parser
Stack-based Buffer Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28346
|
Canon
|
CVE-2025-14231
|
8.8
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) Canon imageCLASS MF654Cdw XML SOAP
Request Parsing Heap-based Buffer Overflow Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-28475
|
QNAP
|
CVE-2025-59389
|
8.0
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) QNAP TS-453E Hyper Data Protector
Plugin query_original_file_size SQL Injection Remote Code
Execution Vulnerability
|
||
|
ZDI-CAN-28358
|
QNAP
|
CVE-2025-59388
|
6.3
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) QNAP TS-453E Hyper Data Protector
Plugin Hard-Coded Credentials Authentication Bypass
Vulnerability
|
||
|
ZDI-CAN-28436
|
QNAP
|
CVE-2025-62849
|
8.0
|
2026-03-16
|
2026-03-17
|
(Pwn2Own) QNAP TS-453E nvrlog_event_add msg SQL
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28435
|
QNAP
|
CVE-2025-62848
|
5.5
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) QNAP TS-453E conn_log_tool Format
String Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28324
|
QNAP
|
CVE-2025-11837
|
8.8
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) QNAP TS-453E malware_remover Code
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-26338
|
ChargePoint
|
CVE-2026-4157
|
7.5
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) ChargePoint Home Flex revssh Service
Command Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-26339
|
ChargePoint
|
CVE-2026-4156
|
7.5
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) ChargePoint Home Flex OCPP getpreq
Stack-based Buffer Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-26340
|
ChargePoint
|
CVE-2026-4155
|
7.5
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) ChargePoint Home Flex Inclusion of
Sensitive Information in Source Code Information Disclosure
Vulnerability
|
||
|
ZDI-CAN-28462
|
Microsoft
|
CVE-2026-21527
|
5.3
|
2026-03-16
|
2026-03-16
|
Microsoft Exchange InterceptorSmtpAgent Improper
Input Validation Security Feature Bypass Vulnerability
|
||
|
ZDI-CAN-17464
|
Linux
|
CVE-2022-1972
|
3.8
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) Linux Kernel nf_tables_newset
Out-Of-Bounds Write Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28345
|
Sonos
|
CVE-2026-4149
|
10.0
|
2026-03-16
|
2026-03-16
|
Sonos Era 300 SMB Response Out-Of-Bounds Access
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-17443
|
Linux
|
CVE-2022-32250
|
8.8
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) Linux Kernel nf_tables Use-After-Free
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-27175
|
VMware
|
CVE-2025-41238
|
8.2
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) VMware Workstation PVSCSI Heap-based
Buffer Overflow Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-27157
|
VMware
|
CVE-2025-41236
|
8.2
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) VMware ESXi VMXNET3 Integer Overflow
Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-27176
|
VMware
|
CVE-2025-41237
|
8.2
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) VMware ESXi VMCI Integer Underflow
Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-19674
|
Synology
|
CVE-2022-45188
|
9.8
|
2026-03-16
|
2026-03-16
|
(Pwn2Own) Synology DiskStation Manager Netatalk
Library Buffer Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27581
|
Fortinet
|
CVE-2026-24018
|
7.8
|
2026-03-10
|
2026-03-10
|
Fortinet FortiClient Link Following Local
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28271
|
Microsoft
|
CVE-2026-25181
|
3.3
|
2026-03-10
|
2026-03-10
|
Microsoft Windows GDI Bitmap Parsing Out-Of-Bound
Read Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28381
|
Microsoft
|
CVE-2026-24289
|
7.8
|
2026-03-10
|
2026-03-10
|
Microsoft Windows NDIS Driver Use-After-Free
Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28498
|
Microsoft
|
CVE-2026-24285
|
7.8
|
2026-03-10
|
2026-03-10
|
Microsoft Windows win32full Improper Release
Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28488
|
Microsoft
|
CVE-2026-24285
|
7.8
|
2026-03-10
|
2026-03-10
|
Microsoft Windows win32full Improper Release
Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28487
|
Microsoft
|
CVE-2026-24285
|
7.8
|
2026-03-10
|
2026-03-10
|
Microsoft Windows win32full Improper Release
Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28247
|
Microsoft
|
CVE-2026-23668
|
8.8
|
2026-03-10
|
2026-03-10
|
Microsoft Windows cdd Improper Locking Local
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28557
|
Microsoft
|
CVE-2026-23668
|
8.8
|
2026-03-10
|
2026-03-10
|
Microsoft Windows win32kfull Improper Locking
Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28159
|
Microsoft
|
CVE-2026-23668
|
8.8
|
2026-03-10
|
2026-03-10
|
Microsoft Windows cdd Improper Locking Local
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-26850
|
Array Networks
|
CVE-2026-26364
|
7.8
|
2026-03-10
|
2026-03-10
|
Array Networks MotionPro ArrayInstallManager
Incorrect Permission Assignment Local Privilege Escalation
Vulnerability
|
||
|
ZDI-CAN-28552
|
Apple
|
CVE-2026-20616
|
7.8
|
2026-03-10
|
2026-03-10
|
Apple macOS libusd_ms Alembic File Parsing
Out-Of-Bounds Write Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28081
|
Apple
|
CVE-2026-20634
|
3.3
|
2026-03-10
|
2026-03-10
|
Apple macOS ImageIO SGI File Parsing
Out-Of-Bounds Read Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28176
|
Apple
|
CVE-2026-20675
|
7.8
|
2026-03-10
|
2026-03-10
|
Apple macOS ImageIO SGI File Parsing Integer
Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28497
|
Apple
|
CVE-2026-20611
|
7.8
|
2026-03-10
|
2026-03-10
|
Apple macOS Audio APAC Frame Decoding
Out-Of-Bounds Write Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28912
|
Unraid
|
CVE-2026-3839
|
7.3
|
2026-03-09
|
2026-03-09
|
Unraid Authentication Request Path Traversal
Authentication Bypass Vulnerability
|
||
|
ZDI-CAN-28951
|
Unraid
|
CVE-2026-3838
|
8.8
|
2026-03-09
|
2026-03-09
|
Unraid Update Request Path Traversal Remote Code
Execution Vulnerability
|
||
|
ZDI-CAN-28911
|
GStreamer
|
CVE-2026-3086
|
7.8
|
2026-03-06
|
2026-03-06
|
GStreamer H.266 Codec Parser Out-Of-Bounds Write
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28910
|
GStreamer
|
CVE-2026-3084
|
7.8
|
2026-03-06
|
2026-03-06
|
GStreamer H.266 Codec Parser Integer Underflow
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28854
|
GStreamer
|
CVE-2026-2921
|
7.8
|
2026-03-06
|
2026-03-06
|
GStreamer RIFF Palette Integer Overflow Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-28851
|
GStreamer
|
CVE-2026-3085
|
8.8
|
2026-03-06
|
2026-03-06
|
GStreamer rtpqdm2depay Heap-based Buffer Overflow
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28850
|
GStreamer
|
CVE-2026-3083
|
8.8
|
2026-03-06
|
2026-03-06
|
GStreamer rtpqdm2depay Out-Of-Bounds Write Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-28845
|
GStreamer
|
CVE-2026-2922
|
7.8
|
2026-03-06
|
2026-03-06
|
GStreamer RealMedia Demuxer Out-Of-Bounds Write
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28843
|
GStreamer
|
CVE-2026-2920
|
7.8
|
2026-03-06
|
2026-03-06
|
GStreamer ASF Demuxer Heap-based Buffer Overflow
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28840
|
GStreamer
|
CVE-2026-3082
|
7.8
|
2026-03-06
|
2026-03-06
|
GStreamer JPEG Parser Heap-based Buffer Overflow
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28839
|
GStreamer
|
CVE-2026-3081
|
7.8
|
2026-03-06
|
2026-03-06
|
GStreamer H.266 Codec Parser Stack-based Buffer
Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28838
|
GStreamer
|
CVE-2026-2923
|
7.8
|
2026-03-06
|
2026-03-06
|
GStreamer DVB Subtitles Out-Of-Bounds Write
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28480
|
Philips
|
CVE-2026-3562
|
6.3
|
2026-03-06
|
2026-03-06
|
(Pwn2Own) Philips Hue Bridge hk_hap Ed25519
Signature Verification Authentication Bypass Vulnerability
|
||
|
ZDI-CAN-28479
|
Philips
|
CVE-2026-3561
|
8.0
|
2026-03-06
|
2026-03-06
|
(Pwn2Own) Philips Hue Bridge hk_hap
characteristics Heap-based Buffer Overflow Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-28469
|
Philips
|
CVE-2026-3560
|
8.8
|
2026-03-06
|
2026-03-06
|
(Pwn2Own) Philips Hue Bridge HomeKit
hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code
Execution Vulnerability
|
||
|
ZDI-CAN-28451
|
Philips
|
CVE-2026-3559
|
8.1
|
2026-03-06
|
2026-03-06
|
(Pwn2Own) Philips Hue Bridge HomeKit Accessory
Protocol Static Nonce Authentication Bypass Vulnerability
|
||
|
ZDI-CAN-28374
|
Philips
|
CVE-2026-3558
|
8.1
|
2026-03-06
|
2026-03-06
|
(Pwn2Own) Philips Hue Bridge HomeKit Accessory
Protocol Transient Pairing Mode Authentication Bypass
Vulnerability
|
||
|
ZDI-CAN-28337
|
Philips
|
CVE-2026-3557
|
8.0
|
2026-03-06
|
2026-03-06
|
(Pwn2Own) Philips Hue Bridge
hap_pair_verify_handler Sub-TLV Parsing Heap-based Buffer
Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28326
|
Philips
|
CVE-2026-3556
|
8.8
|
2026-03-06
|
2026-03-06
|
(Pwn2Own) Philips Hue Bridge HomeKit Pair-Setup
Heap-based Buffer Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28276
|
Philips
|
CVE-2026-3555
|
8.0
|
2026-03-06
|
2026-03-06
|
(Pwn2Own) Philips Hue Bridge Zigbee Stack Custom
Command Handler Heap-based Buffer Overflow Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-28304
|
Docker
|
CVE-2025-15558
|
7.8
|
2026-03-06
|
2026-03-06
|
Docker Desktop Docker Plugins Uncontrolled Search
Path Element Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28415
|
Delta Electronics
|
CVE-2026-3094
|
7.8
|
2026-03-06
|
2026-03-06
|
Delta Electronics CNCSoft-G2 DPAX File Parsing
Out-Of-Bounds Write Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28379
|
Docker
|
CVE-2026-28400
|
7.3
|
2026-03-03
|
2026-03-03
|
Docker Desktop for Mac Docker Model Runner
Exposed Dangerous Function Denial-of-Service Vulnerability
|
||
|
ZDI-CAN-28218
|
Trend Micro
|
CVE-2025-71218
|
5.0
|
2026-03-03
|
2026-03-03
|
Trend Micro Cleaner One Pro Link Following
Denial-of-Service Vulnerability
|
||
|
ZDI-CAN-26039
|
Trend Micro
|
CVE-2025-71209
|
8.1
|
2026-03-03
|
2026-03-03
|
Trend Micro Apex Central Improper Authentication
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-26037
|
Trend Micro
|
CVE-2025-71208
|
8.1
|
2026-03-03
|
2026-03-03
|
Trend Micro Apex Central Improper Authentication
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-26597
|
Trend Micro
|
CVE-2025-71207
|
4.4
|
2026-03-03
|
2026-03-03
|
Trend Micro Apex Central Manual Update
Server-Side Request Forgery Vulnerability
|
||
|
ZDI-CAN-26598
|
Trend Micro
|
CVE-2025-71206
|
4.4
|
2026-03-03
|
2026-03-03
|
Trend Micro Apex Central Scheduled Update
Server-Side Request Forgery Vulnerability
|
||
|
ZDI-CAN-26618
|
Trend Micro
|
CVE-2025-71205
|
4.4
|
2026-03-03
|
2026-03-03
|
Trend Micro Apex Central Hub Server Server-Side
Request Forgery Vulnerability
|
||
|
ZDI-CAN-26594
|
Trend Micro
|
CVE-2025-71217
|
7.8
|
2026-03-03
|
2026-03-03
|
Trend Micro Apex One Security Agent TmSelfProtect
Origin Validation Error Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-26605
|
Trend Micro
|
CVE-2025-71216
|
7.8
|
2026-03-03
|
2026-03-03
|
Trend Micro Apex One Security Agent Cache
Mechanism Time-Of-Check Time-Of-Use Local Privilege Escalation
Vulnerability
|
||
|
ZDI-CAN-26609
|
Trend Micro
|
CVE-2025-71215
|
7.8
|
2026-03-03
|
2026-03-03
|
Trend Micro Apex One Security Agent iCore Service
Signature Verification Time-Of-Check Time-Of-Use Local Privilege
Escalation Vulnerability
|
||
|
ZDI-CAN-26771
|
Trend Micro
|
CVE-2025-71213
|
7.8
|
2026-03-03
|
2026-03-03
|
Trend Micro Apex One Origin Validation Error
Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-26282
|
Trend Micro
|
CVE-2025-71214
|
7.8
|
2026-03-03
|
2026-03-03
|
Trend Micro Apex One Security Agent iCore Service
Origin Validation Error Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-24972
|
Trend Micro
|
CVE-2025-71212
|
7.8
|
2026-03-03
|
2026-03-03
|
Trend Micro Apex One Virus Scan Engine Link
Following Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28002
|
Trend Micro
|
CVE-2025-71211
|
9.8
|
2026-03-03
|
2026-03-03
|
Trend Micro Apex One Console Directory Traversal
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28001
|
Trend Micro
|
CVE-2025-71210
|
9.8
|
2026-03-03
|
2026-03-03
|
Trend Micro Apex One Console Directory Traversal
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28385
|
LangChain
|
CVE-2026-27794
|
8.1
|
2026-03-03
|
2026-03-03
|
LangChain LangGraph BaseCache Deserialization of
Untrusted Data Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27634
|
Hewlett Packard Enterprise
|
CVE-2026-23600
|
7.3
|
2026-03-03
|
2026-03-03
|
Hewlett Packard Enterprise AutoPass License
Server Authentication Bypass Vulnerability
|
||
|
ZDI-CAN-28235
|
Music Assistant
|
CVE-2026-26975
|
8.8
|
2026-03-03
|
2026-03-03
|
(Pwn2Own) Music Assistant _update_library_item
External Control of File Path Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-28108
|
Siemens
|
CVE-2026-25656
|
7.8
|
2026-02-25
|
2026-02-25
|
Siemens SINEC NMS Uncontrolled Search Path
Element Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28107
|
Siemens
|
CVE-2026-25655
|
7.8
|
2026-02-25
|
2026-02-25
|
Siemens SINEC NMS Uncontrolled Search Path
Element Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-25440
|
IceWarp
|
CVE-2026-2493
|
7.5
|
2026-02-25
|
2026-02-25
|
IceWarp collaboration Directory Traversal
Information Disclosure Vulnerability
|
||
|
ZDI-CAN-23993
|
Socomec
|
CVE-2026-2491
|
6.3
|
2026-02-25
|
2026-02-25
|
Socomec DIRIS A-40 HTTP API Authentication Bypass
Vulnerability
|
||
|
ZDI-CAN-28824
|
Ubiquiti Networks
|
CVE-2026-21634
|
6.5
|
2026-02-25
|
2026-02-25
|
(Pwn2Own) Ubiquiti Networks AI Pro Uncaught
Exception Denial-of-Service Vulnerability
|
||
|
ZDI-CAN-28474
|
Ubiquiti Networks
|
CVE-2026-21633
|
5.3
|
2026-02-25
|
2026-02-25
|
(Pwn2Own) Ubiquiti Networks AI Pro Cleartext
Transmission Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28274
|
Ubiquiti Networks
|
CVE-2026-21633
|
5.4
|
2026-02-25
|
2026-02-25
|
(Pwn2Own) Ubiquiti Networks AI Pro Discovery
Protocol Missing Encryption Protocol Downgrade Vulnerability
|
||
|
ZDI-CAN-28631
|
Docker
|
CVE-2026-2664
|
6.5
|
2026-02-25
|
2026-02-25
|
Docker Desktop grpcfuse Kernel Module
Out-Of-Bounds Read Information Disclosure Vulnerability
|
||
|
ZDI-CAN-27785
|
claude-hovercraft
|
CVE-2025-15060
|
9.8
|
2026-02-25
|
2026-02-25
|
claude-hovercraft executeClaudeCode Command
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27562
|
Docker
|
|
5.5
|
2026-02-23
|
2026-02-23
|
Docker Desktop MCP Server Cleartext Storage of
Sensitive Information Vulnerability
|
||
|
ZDI-CAN-27788
|
PDF-XChange
|
CVE-2026-2040
|
7.3
|
2026-02-19
|
2026-02-19
|
PDF-XChange Editor TrackerUpdate Uncontrolled
Search Path Element Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28591
|
GIMP
|
CVE-2026-2048
|
7.8
|
2026-02-19
|
2026-02-19
|
GIMP XWD File Parsing Out-Of-Bounds Write Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-28530
|
GIMP
|
CVE-2026-2047
|
7.8
|
2026-02-19
|
2026-02-19
|
GIMP ICNS File Parsing Heap-based Buffer Overflow
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28265
|
GIMP
|
CVE-2026-2045
|
7.8
|
2026-02-19
|
2026-02-19
|
GIMP XWD File Parsing Out-Of-Bounds Write Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-28158
|
GIMP
|
CVE-2026-2044
|
7.8
|
2026-02-19
|
2026-02-19
|
GIMP PGM File Parsing Uninitialized Memory Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-27909
|
RustDesk
|
CVE-2026-2490
|
5.5
|
2026-02-19
|
2026-02-19
|
RustDesk Client for Windows Transfer File Link
Following Information Disclosure Vulnerability
|
||
|
ZDI-CAN-25480
|
TensorFlow
|
CVE-2026-2492
|
7.0
|
2026-02-19
|
2026-02-19
|
TensorFlow HDF5 Library Uncontrolled Search Path
Element Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-25710
|
Fortinet
|
CVE-2025-62676
|
7.8
|
2026-02-19
|
2026-02-19
|
Fortinet FortiClient VPN FCConfig Utility Link
Following Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28404
|
Dassault Systèmes
|
CVE-2026-1335
|
7.8
|
2026-02-19
|
2026-02-19
|
Dassault Systèmes eDrawings Viewer EPRT File
Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28378
|
Dassault Systèmes
|
CVE-2026-1334
|
7.8
|
2026-02-19
|
2026-02-19
|
Dassault Systèmes eDrawings Viewer EPRT File
Parsing Memory Corruption Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28315
|
Dassault Systèmes
|
CVE-2026-1333
|
7.8
|
2026-02-19
|
2026-02-19
|
Dassault Systèmes eDrawings Viewer EPRT File
Parsing Uninitialized Variable Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-28256
|
MLflow
|
CVE-2026-2635
|
9.8
|
2026-02-19
|
2026-02-19
|
MLflow Use of Default Password Authentication
Bypass Vulnerability
|
||
|
ZDI-CAN-28112
|
Bosch Rexroth
|
CVE-2025-60037, CVE-2025-60038
|
7.8
|
2026-02-19
|
2026-02-19
|
Bosch Rexroth IndraWorks Print Settings File
Parsing Deserialization Of Untrusted Data Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-27994
|
Bosch Rexroth
|
CVE-2025-60035
|
7.8
|
2026-02-19
|
2026-02-19
|
Bosch Rexroth IndraWorks OPC.TestClient XML File
Parsing Deserialization Of Untrusted Data Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-27996
|
Bosch Rexroth
|
CVE-2025-60036
|
7.8
|
2026-02-19
|
2026-02-19
|
Bosch Rexroth IndraWorks UA.TestClient XML File
Parsing Deserialization Of Untrusted Data Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-28581
|
Autodesk
|
CVE-2026-0875
|
7.8
|
2026-02-18
|
2026-02-18
|
Autodesk AutoCAD MODEL File Out-Of-Bounds Write
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28417
|
Autodesk
|
CVE-2026-0874
|
7.8
|
2026-02-18
|
2026-02-18
|
Autodesk AutoCAD CATPART File Parsing
Out-Of-Bounds Write Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-26649
|
MLflow
|
CVE-2026-2033
|
8.1
|
2026-02-13
|
2026-02-13
|
MLflow Tracking Server Artifact Handler Directory
Traversal Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28129
|
Sante
|
CVE-2026-2034
|
7.8
|
2026-02-13
|
2026-02-13
|
Sante DICOM Viewer Pro DCM File Parsing Buffer
Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27923
|
Oracle
|
CVE-2026-21956
|
8.2
|
2026-02-13
|
2026-02-13
|
Oracle VirtualBox VMSVGA Out-Of-Bounds Access
Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-27938
|
Oracle
|
CVE-2026-21957
|
7.5
|
2026-02-13
|
2026-02-13
|
Oracle VirtualBox VMSVGA Out-Of-Bounds Write
Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28080
|
Oracle
|
CVE-2026-21963
|
6.0
|
2026-02-13
|
2026-02-13
|
Oracle VirtualBox BusLogic Uninitialized Memory
Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28079
|
Oracle
|
CVE-2026-21985
|
6.0
|
2026-02-13
|
2026-02-13
|
Oracle VirtualBox LsiLogic Uninitialized Memory
Information Disclosure Vulnerability
|
||
|
ZDI-CAN-27925
|
Oracle
|
CVE-2026-21984
|
7.5
|
2026-02-13
|
2026-02-13
|
Oracle VirtualBox VMSVGA Race Condition Local
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-27870
|
Oracle
|
CVE-2026-21955
|
8.2
|
2026-02-13
|
2026-02-13
|
Oracle VirtualBox VMSVGA Use-After-Free Local
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28045
|
Oracle
|
CVE-2026-21983
|
7.5
|
2026-02-13
|
2026-02-13
|
Oracle VirtualBox VMSVGA Heap-based Buffer
Overflow Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28186
|
Dassault Systèmes
|
CVE-2026-1283
|
7.8
|
2026-02-13
|
2026-02-13
|
Dassault Systèmes eDrawings Viewer EPRT File
Parsing Heap-based Buffer Overflow Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-28188
|
Dassault Systèmes
|
CVE-2026-1284
|
7.8
|
2026-02-13
|
2026-02-13
|
Dassault Systèmes eDrawings Viewer EPRT File
Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27478
|
Schneider Electric
|
CVE-2025-13845
|
7.8
|
2026-02-12
|
2026-02-12
|
Schneider Electric EcoStruxure Power Build SSD
File Parsing Use-After-Free Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27480
|
Schneider Electric
|
CVE-2025-13845
|
7.8
|
2026-02-12
|
2026-02-12
|
Schneider Electric EcoStruxure Power Build SSD
File Parsing Use-After-Free Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27455
|
Schneider Electric
|
CVE-2025-13845
|
7.8
|
2026-02-12
|
2026-02-12
|
Schneider Electric EcoStruxure Power Build SSD
File Parsing Memory Corruption Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-27362
|
Schneider Electric
|
CVE-2025-13845
|
7.8
|
2026-02-12
|
2026-02-12
|
Schneider Electric EcoStruxure Power Build SSD
File Parsing Memory Corruption Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-27364
|
Schneider Electric
|
CVE-2025-13845
|
7.8
|
2026-02-12
|
2026-02-12
|
Schneider Electric EcoStruxure Power Build SSD
File Parsing Memory Corruption Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-27374
|
Schneider Electric
|
CVE-2025-13845
|
7.8
|
2026-02-12
|
2026-02-12
|
Schneider Electric EcoStruxure Power Build SSD
File Parsing Memory Corruption Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-27390
|
Schneider Electric
|
CVE-2025-13845
|
7.8
|
2026-02-12
|
2026-02-12
|
Schneider Electric EcoStruxure Power Build SSD
File Parsing Memory Corruption Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-27363
|
Schneider Electric
|
CVE-2025-13845
|
7.8
|
2026-02-12
|
2026-02-12
|
Schneider Electric EcoStruxure Power Build SSD
File Parsing Memory Corruption Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-27370
|
Schneider Electric
|
CVE-2025-13845
|
7.8
|
2026-02-12
|
2026-02-12
|
Schneider Electric EcoStruxure Power Build SSD
File Parsing Memory Corruption Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-27368
|
Schneider Electric
|
CVE-2025-13845
|
7.8
|
2026-02-12
|
2026-02-12
|
Schneider Electric EcoStruxure Power Build SSD
File Parsing Memory Corruption Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-27371
|
Schneider Electric
|
CVE-2025-13845
|
7.8
|
2026-02-12
|
2026-02-12
|
Schneider Electric EcoStruxure Power Build SSD
File Parsing Memory Corruption Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-28491
|
Microsoft
|
CVE-2026-21249
|
3.3
|
2026-02-12
|
2026-02-12
|
Microsoft Windows searchConnector-ms NTLM
Response Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28410
|
Microsoft
|
CVE-2026-21527
|
5.3
|
2026-02-12
|
2026-02-12
|
Microsoft Exchange InterceptorSmtpAgent Reliance
on Untrusted Inputs Security Feature Bypass Vulnerability
|
||
|
ZDI-CAN-28066
|
Microsoft
|
CVE-2026-21235
|
8.8
|
2026-02-12
|
2026-02-12
|
Microsoft Windows win32kfull Use-After-Free Local
Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-26885
|
Ivanti
|
CVE-2026-1603
|
8.6
|
2026-02-12
|
2026-02-12
|
Ivanti Endpoint Manager AuthHelper Authentication
Bypass Vulnerability
|
||
|
ZDI-CAN-26863
|
Ivanti
|
CVE-2026-1602
|
7.2
|
2026-02-12
|
2026-02-12
|
Ivanti Endpoint Manager ROI SQL Injection Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-28131
|
Deciso
|
CVE-2026-2035
|
6.8
|
2026-02-12
|
2026-02-12
|
Deciso OPNsense diag_backup.php filename Command
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28597
|
GFI
|
CVE-2026-2039
|
7.3
|
2026-02-12
|
2026-02-12
|
GFI Archiver MArc.Store Missing Authorization
Authentication Bypass Vulnerability
|
||
|
ZDI-CAN-27936
|
GFI
|
CVE-2026-2036
|
8.8
|
2026-02-12
|
2026-02-12
|
GFI Archiver MArc.Store Deserialization of
Untrusted Data Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27934
|
GFI
|
CVE-2026-2038
|
7.3
|
2026-02-12
|
2026-02-12
|
GFI Archiver MArc.Core Missing Authorization
Authentication Bypass Vulnerability
|
||
|
ZDI-CAN-27935
|
GFI
|
CVE-2026-2037
|
8.8
|
2026-02-12
|
2026-02-12
|
GFI Archiver MArc.Core Deserialization of
Untrusted Data Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28250
|
Nagios
|
CVE-2026-2041
|
7.2
|
2026-02-12
|
2026-02-12
|
Nagios Host zabbixagent_configwizard_func Command
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28249
|
Nagios
|
CVE-2026-2043
|
7.2
|
2026-02-12
|
2026-02-12
|
Nagios Host esensors_websensor_configwizard_func
Command Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28245
|
Nagios
|
CVE-2026-2042
|
7.2
|
2026-02-12
|
2026-02-12
|
Nagios Host monitoringwizard Command Injection
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27940
|
Adobe
|
CVE-2025-61808
|
7.2
|
2026-02-06
|
2026-02-06
|
Adobe ColdFusion CAR File Parsing Directory
Traversal Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-26034
|
Xmind
|
CVE-2026-0777
|
7.8
|
2026-02-06
|
2026-02-13
|
(0Day) Xmind Attachment Insufficient UI Warning
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28542
|
Docker
|
CVE-2025-14740
|
6.7
|
2026-02-05
|
2026-02-05
|
Docker Desktop for Windows Incorrect Permission
Assignment Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28190
|
Docker
|
CVE-2025-14740
|
6.7
|
2026-02-05
|
2026-02-05
|
Docker Desktop for Windows Incorrect Permission
Assignment Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-28333
|
Lexmark
|
CVE-2025-65079
|
8.8
|
2026-02-05
|
2026-02-05
|
(Pwn2Own) Lexmark CX532adwe getCFFNames
Heap-based Buffer Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28328
|
Lexmark
|
CVE-2025-65080
|
8.8
|
2026-02-05
|
2026-02-05
|
(Pwn2Own) Lexmark CX532adwe usecmap Type
Confusion Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28341
|
Lexmark
|
CVE-2025-65081
|
8.8
|
2026-02-05
|
2026-02-18
|
(Pwn2Own) Lexmark CX532adwe execuserobject
Heap-based Buffer Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28261
|
Lexmark
|
CVE-2025-65077
|
8.8
|
2026-02-05
|
2026-02-10
|
(Pwn2Own) Lexmark CX532adwe libesffls Directory
Traversal Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28477
|
Lexmark
|
CVE-2025-65078
|
7.8
|
2026-02-05
|
2026-02-10
|
(Pwn2Own) Lexmark CX532adwe esfhelper Untrusted
Search Path Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-26889
|
NVIDIA
|
CVE-2025-33201
|
7.5
|
2026-02-04
|
2026-02-04
|
NVIDIA Triton Inference Server EVBufferToJson
Uncaught Exception Denial-of-Service Vulnerability
|
||
|
ZDI-CAN-27989
|
NVIDIA
|
CVE-2026-24149
|
7.8
|
2026-02-04
|
2026-02-04
|
NVIDIA Megatron-LM load_base_checkpoint
Deserialization of Untrusted Data Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-26000
|
CyberArk
|
CVE-2025-66374
|
7.0
|
2026-02-03
|
2026-02-04
|
CyberArk Endpoint Privilege Management Improper
Privilege Management Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-27641
|
AzeoTech
|
CVE-2025-66589
|
7.8
|
2026-02-03
|
2026-02-03
|
AzeoTech DAQFactory Pro CTL File Parsing
Out-Of-Bounds Read Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28285
|
Apple
|
CVE-2025-46298
|
8.8
|
2026-02-03
|
2026-02-03
|
Apple Safari JavaScriptCore FTL New Array
Materialization Type Confusion Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-28035
|
Apple
|
CVE-2025-43283
|
6.5
|
2026-02-03
|
2026-02-03
|
Apple macOS AppleIntelKBLGraphics Out-Of-Bounds
Read Information Disclosure Vulnerability
|
||
|
ZDI-CAN-27596
|
Progress Software
|
CVE-2025-13447
|
6.4
|
2026-02-02
|
2026-02-02
|
Progress Software Kemp LoadMaster addapikey
Command Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27595
|
Progress Software
|
CVE-2025-13447
|
6.8
|
2026-02-02
|
2026-02-02
|
Progress Software Kemp LoadMaster delapikey OS
Command Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27591
|
Progress Software
|
CVE-2025-13447
|
6.4
|
2026-02-02
|
2026-02-02
|
Progress Software Kemp LoadMaster listapikeys
Command Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27593
|
Progress Software
|
CVE-2025-13444
|
7.1
|
2026-02-02
|
2026-02-02
|
Progress Software Kemp LoadMaster getcipherset
Command Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27594
|
Progress Software
|
CVE-2025-13447
|
7.1
|
2026-02-02
|
2026-02-02
|
Progress Software Kemp LoadMaster delcert Command
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28599
|
GIMP
|
CVE-2026-0797
|
7.8
|
2026-01-30
|
2026-01-30
|
GIMP ICO File Parsing Heap-based Buffer Overflow
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27093
|
Delta Electronics
|
CVE-2026-0975
|
7.8
|
2026-01-28
|
2026-01-28
|
Delta Electronics DIAView Exposed Dangerous
Method Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27307
|
Fortinet
|
CVE-2025-67685
|
8.8
|
2026-01-28
|
2026-01-28
|
Fortinet FortiSandbox fortisandbox Server-Side
Request Forgery Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-26620
|
Hancom
|
CVE-2025-29867
|
7.8
|
2026-01-28
|
2026-01-28
|
Hancom Office DOC File Parsing Type Confusion
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27892
|
Cisco
|
CVE-2026-20026
|
9.8
|
2026-01-28
|
2026-01-28
|
Cisco Snort _bnfa_search_csparse_nfa
Use-After-Free Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27893
|
Cisco
|
CVE-2026-20027
|
5.3
|
2026-01-28
|
2026-01-28
|
Cisco Snort _bnfa_search_csparse_nfa
Out-Of-Bounds Read Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28082
|
Microsoft
|
CVE-2026-20871
|
7.8
|
2026-01-13
|
2026-01-13
|
Microsoft Windows Desktop Window Manager
Use-After-Free Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-25430
|
npm
|
CVE-2026-0775
|
7.8
|
2026-01-12
|
2026-02-02
|
(0Day) npm cli Uncontrolled Search Path Element
Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-26845
|
Upsonic
|
CVE-2026-0773
|
9.8
|
2026-01-09
|
2026-01-09
|
(0Day) Upsonic Cloudpickle Deserialization of
Untrusted Data Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-23285
|
Enel X
|
CVE-2026-0778
|
8.8
|
2026-01-09
|
2026-01-09
|
(0Day) (Pwn2Own) Enel X JuiceBox 40 Telnet
Service Missing Authentication Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-27057
|
Discord
|
CVE-2026-0776
|
7.3
|
2026-01-09
|
2026-01-09
|
(0Day) Discord Client Uncontrolled Search Path
Element Local Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-26708
|
WatchYourLAN
|
CVE-2026-0774
|
8.8
|
2026-01-09
|
2026-01-09
|
(0Day) WatchYourLAN Configuration Page Argument
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27919
|
Langflow
|
CVE-2026-0772
|
7.5
|
2026-01-09
|
2026-01-09
|
(0Day) Langflow Disk Cache Deserialization of
Untrusted Data Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27497
|
Langflow
|
CVE-2026-0771
|
7.1
|
2026-01-09
|
2026-01-09
|
(0Day) Langflow PythonFunction Code Injection
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27325
|
Langflow
|
CVE-2026-0770
|
9.8
|
2026-01-09
|
2026-01-09
|
(0Day) Langflow exec_globals Inclusion of
Functionality from Untrusted Control Sphere Remote Code
Execution Vulnerability
|
||
|
ZDI-CAN-26972
|
Langflow
|
CVE-2026-0769
|
9.8
|
2026-01-09
|
2026-01-09
|
(0Day) Langflow eval_custom_component_code Eval
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27322
|
Langflow
|
CVE-2026-0768
|
9.8
|
2026-01-09
|
2026-01-09
|
(0Day) Langflow code Code Injection Remote Code
Execution Vulnerability
|
||
|
ZDI-CAN-28259
|
Open WebUI
|
CVE-2026-0767
|
5.3
|
2026-01-09
|
2026-01-09
|
(0Day) Open WebUI Cleartext Transmission of
Credentials Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28257
|
Open WebUI
|
CVE-2026-0766
|
8.8
|
2026-01-09
|
2026-01-09
|
(0Day) Open WebUI load_tool_module_by_id Command
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28258
|
Open WebUI
|
CVE-2026-0765
|
8.8
|
2026-01-09
|
2026-01-09
|
(0Day) Open WebUI PIP
install_frontmatter_requirements Command Injection Remote Code
Execution Vulnerability
|
||
|
ZDI-CAN-27957
|
GPT Academic
|
CVE-2026-0764
|
9.8
|
2026-01-09
|
2026-01-09
|
(0Day) GPT Academic upload Deserialization of
Untrusted Data Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27958
|
GPT Academic
|
CVE-2026-0763
|
9.8
|
2026-01-09
|
2026-01-09
|
(0Day) GPT Academic
run_in_subprocess_wrapper_func Deserialization of Untrusted Data
Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27956
|
GPT Academic
|
CVE-2026-0762
|
8.1
|
2026-01-09
|
2026-01-09
|
(0Day) GPT Academic stream_daas Deserialization
of Untrusted Data Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28124
|
Foundation Agents
|
CVE-2026-0761
|
9.8
|
2026-01-09
|
2026-01-09
|
(0Day) Foundation Agents MetaGPT
actionoutput_str_to_mapping Code Injection Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-28121
|
Foundation Agents
|
CVE-2026-0760
|
9.8
|
2026-01-09
|
2026-01-09
|
(0Day) Foundation Agents MetaGPT
deserialize_message Deserialization of Untrusted Data Remote
Code Execution Vulnerability
|
||
|
ZDI-CAN-27786
|
Katana Network
|
CVE-2026-0759
|
9.8
|
2026-01-09
|
2026-01-09
|
(0Day) Katana Network Development Starter Kit
executeCommand Command Injection Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-27910
|
mcp-server-siri-shortcuts
|
CVE-2026-0758
|
7.8
|
2026-01-09
|
2026-01-09
|
(0Day) mcp-server-siri-shortcuts shortcutName
Command Injection Privilege Escalation Vulnerability
|
||
|
ZDI-CAN-27810
|
MCP Manager for Claude Desktop
|
CVE-2026-0757
|
8.8
|
2026-01-09
|
2026-01-09
|
(0Day) MCP Manager for Claude Desktop
execute-command Command Injection Sandbox Escape Vulnerability
|
||
|
ZDI-CAN-27784
|
github-kanban-mcp-server
|
CVE-2026-0756
|
9.8
|
2026-01-09
|
2026-01-09
|
(0Day) github-kanban-mcp-server execAsync Command
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27783
|
Gemini MCP Tool
|
CVE-2026-0755
|
9.8
|
2026-01-09
|
2026-01-09
|
(0Day) gemini-mcp-tool execAsync Command
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27683
|
Ollama MCP Server
|
CVE-2025-15063
|
9.8
|
2026-01-09
|
2026-01-09
|
(0Day) Ollama MCP Server execAsync Command
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-27889
|
Cisco
|
CVE-2026-20029
|
4.9
|
2026-01-09
|
2026-01-09
|
Cisco Identity Services Engine
getSpecificPLRfromAuthCode XML External Entity Processing
Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28322
|
ALGO
|
CVE-2026-0796
|
7.2
|
2026-01-09
|
2026-01-09
|
(0Day) ALGO 8180 IP Audio Alerter Web UI Command
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28321
|
ALGO
|
CVE-2026-0795
|
7.2
|
2026-01-09
|
2026-01-09
|
(0Day) ALGO 8180 IP Audio Alerter Web UI Command
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28303
|
ALGO
|
CVE-2026-0794
|
8.1
|
2026-01-09
|
2026-01-09
|
(0Day) ALGO 8180 IP Audio Alerter SIP
Use-After-Free Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28302
|
ALGO
|
CVE-2026-0793
|
8.1
|
2026-01-09
|
2026-01-09
|
(0Day) ALGO 8180 IP Audio Alerter InformaCast
Heap-based Buffer Overflow Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28301
|
ALGO
|
CVE-2026-0792
|
8.1
|
2026-01-09
|
2026-01-09
|
(0Day) ALGO 8180 IP Audio Alerter SIP INVITE
Alert-Info Stack-based Buffer Overflow Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-28300
|
ALGO
|
CVE-2026-0791
|
8.1
|
2026-01-09
|
2026-01-09
|
(0Day) ALGO 8180 IP Audio Alerter SIP INVITE
Replaces Stack-based Buffer Overflow Remote Code Execution
Vulnerability
|
||
|
ZDI-CAN-28299
|
ALGO
|
CVE-2026-0790
|
5.3
|
2026-01-09
|
2026-01-09
|
(0Day) ALGO 8180 IP Audio Alerter Web UI Direct
Request Information Disclosure Vulnerability
|
||
|
ZDI-CAN-28297
|
ALGO
|
CVE-2026-0789
|
5.3
|
2026-01-09
|
2026-01-09
|
(0Day) ALGO 8180 IP Audio Alerter Web UI
Inclusion of Authentication Cookie in Response Body Information
Disclosure Vulnerability
|
||
|
ZDI-CAN-28298
|
ALGO
|
CVE-2026-0788
|
5.3
|
2026-01-09
|
2026-01-09
|
(0Day) ALGO 8180 IP Audio Alerter Web UI
Persistent Cross-Site Scripting Vulnerability
|
||
|
ZDI-CAN-28296
|
ALGO
|
CVE-2026-0787
|
8.1
|
2026-01-09
|
2026-01-09
|
(0Day) ALGO 8180 IP Audio Alerter SAC Command
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28295
|
ALGO
|
CVE-2026-0786
|
7.5
|
2026-01-09
|
2026-01-09
|
(0Day) ALGO 8180 IP Audio Alerter SCI Command
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28294
|
ALGO
|
CVE-2026-0785
|
7.5
|
2026-01-09
|
2026-01-09
|
(0Day) ALGO 8180 IP Audio Alerter API Command
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28293
|
ALGO
|
CVE-2026-0784
|
7.2
|
2026-01-09
|
2026-01-09
|
(0Day) ALGO 8180 IP Audio Alerter Web UI Command
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28292
|
ALGO
|
CVE-2026-0783
|
7.2
|
2026-01-09
|
2026-01-09
|
(0Day) ALGO 8180 IP Audio Alerter Web UI Command
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28291
|
ALGO
|
CVE-2026-0782
|
7.2
|
2026-01-09
|
2026-01-09
|
(0Day) ALGO 8180 IP Audio Alerter Web UI Command
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28290
|
ALGO
|
CVE-2026-0781
|
7.2
|
2026-01-09
|
2026-01-09
|
(0Day) ALGO 8180 IP Audio Alerter Web UI Command
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-28289
|
ALGO
|
CVE-2026-0780
|
7.2
|
2026-01-09
|
2026-01-09
|
(0Day) ALGO 8180 IP Audio Alerter Web UI Command
Injection Remote Code Execution Vulnerability
|
||
|
ZDI-CAN-25568
|
ALGO
|
CVE-2026-0779
|
7.2
|
2026-01-09
|
2026-01-09
|
(0Day) ALGO 8180 IP Audio Alerter Ping Command
Injection Remote Code Execution Vulnerability
|