jell.ie CVEs

Read at: 2026-09-01T19:11:19+00:00

CVE-2026-52022 - Kamailio IMS P-CSCF Denial of Service Vulnerability

CVE ID :CVE-2026-52022
Published : Sept. 1, 2026, 6:17 p.m. | 13 minutes ago
Description :An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registration handling components
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 6:17 pm UTC

CVE-2026-52131 - llama.cpp Reachable Assertion Vulnerability

CVE ID :CVE-2026-52131
Published : Sept. 1, 2026, 6:17 p.m. | 13 minutes ago
Description :llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 6:17 pm UTC

CVE-2026-52295 - FFmpeg libavformat Buffer Overflow

CVE ID :CVE-2026-52295
Published : Sept. 1, 2026, 6:17 p.m. | 13 minutes ago
Description :Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows an attacker to cause a denial of service via the libavformat/iamf_writer.c component
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 6:17 pm UTC

CVE-2026-52023 - Kamailio ims_registrar_pcscf Module Denial of Service Vulnerability

CVE ID :CVE-2026-52023
Published : Sept. 1, 2026, 6:17 p.m. | 13 minutes ago
Description :An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec_agree()
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 6:17 pm UTC

CVE-2026-52132 - llama.cpp Denial of Service Vulnerability

CVE ID :CVE-2026-52132
Published : Sept. 1, 2026, 6:17 p.m. | 13 minutes ago
Description :llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a negative top_n value in a POST request to /rerank.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 6:17 pm UTC

CVE-2026-51974 - Fooocus Code Injection Vulnerability

CVE ID :CVE-2026-51974
Published : Sept. 1, 2026, 6:17 p.m. | 13 minutes ago
Description :An eval() injection vulnerability in the get_list function in modules/meta_parser.py in lllyasviel Fooocus 2.1.854 through 2.5.5 allows remote attackers to execute arbitrary Python code via a crafted styles payload in the EXIF metadata of an uploaded image file.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 6:17 pm UTC

CVE-2026-52111 - Fast-Note-Sync-Service Privilege Escalation Vulnerability

CVE ID :CVE-2026-52111
Published : Sept. 1, 2026, 6:17 p.m. | 13 minutes ago
Description :An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes authTokenKey
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 6:17 pm UTC

CVE-2026-52130 - llama.cpp Uncontrolled Recursion Denial of Service

CVE ID :CVE-2026-52130
Published : Sept. 1, 2026, 6:17 p.m. | 13 minutes ago
Description :llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to-grammar.cpp, resulting in a denial of service.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 6:17 pm UTC

CVE-2026-19593 - OpenAI Codex Arbitrary Code Execution Vulnerability

CVE ID :CVE-2026-19593
Published : Sept. 1, 2026, 6:17 p.m. | 13 minutes ago
Description :OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree setting and a configured clean or process filter can cause Git to run an attacker-controlled program. The program runs outside Codex's command sandbox with the signed-in user's privileges, without a workspace-trust prompt, command approval, or interaction with a model. The attacker can read, modify, or delete files and access credentials available to that user. Exploitation requires Git to be available on PATH and the user to open the attacker-prepared repository with its local Git configuration intact. An ordinary Git clone does not copy the source repository's .git/config and is not sufficient by itself.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 6:17 pm UTC

CVE-2026-19592 - OpenAI Codex Arbitrary Code Execution Vulnerability

CVE ID :CVE-2026-19592
Published : Sept. 1, 2026, 6:17 p.m. | 13 minutes ago
Description :OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS automatically collected Git repository metadata without disabling the repository-local core.fsmonitor setting. If a user opens or uses an attacker-prepared repository whose preserved .git/config sets core.fsmonitor to an attacker-controlled filesystem-monitor helper, Git can execute that helper while Codex collects repository metadata. The helper runs outside Codex's command sandbox and without a user-approval prompt, allowing attacker-controlled code to run with the user's privileges. The code can read, change, or delete the user's files and access other resources available to the user's account. An ordinary Git clone does not preserve the source repository's local .git/config; exploitation requires a repository delivered or copied with that configuration intact.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 6:17 pm UTC

CVE-2026-19591 - OpenAI Codex Command Injection Vulnerability

CVE ID :CVE-2026-19591
Published : Sept. 1, 2026, 6:17 p.m. | 13 minutes ago
Description :OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's stop-parsing token (--%) differently than PowerShell itself. If a user opens an attacker-prepared repository and Codex follows its instructions, Codex can run a file-writing Git command without requesting user approval. On macOS and Linux, exploitation additionally requires separately installed PowerShell Core (pwsh) to be invoked. If filesystem protections permit the write, the command can modify Codex's configuration. If Codex later loads the modified configuration, it can launch an attacker-controlled MCP server and execute code with the user's privileges, allowing it to read, change, or delete files accessible to that account. The approval bypass does not disable filesystem sandboxing; the default filesystem sandbox on macOS and Linux can prevent writes outside permitted locations.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 6:17 pm UTC

CVE-2026-19590 - OpenAI Codex Arbitrary Code Execution via Git Hooks

CVE ID :CVE-2026-19590
Published : Sept. 1, 2026, 6:17 p.m. | 13 minutes ago
Description :OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath setting. If a user opens an attacker-prepared repository whose preserved .git/config points core.hooksPath to an attacker-controlled directory, Codex can run a malicious hook while processing the repository. The hook executes outside Codex's command sandbox, without user approval, and with the user's privileges, allowing it to read, change, or delete the user's files and access other resources available to the user's account. An ordinary Git clone does not preserve the attacker-controlled repository-local configuration required for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 6:17 pm UTC

CVE-2024-7952 - DataEdgePlatform DataMosaix™ Private Cloud

CVE ID :CVE-2024-7952
Published : Sept. 1, 2026, 6:17 p.m. | 13 minutes ago
Description :A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be reached without authentication. If exploited, a threat actor could view customer data.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 6:17 pm UTC

CVE-2024-7953 - DataEdgePlatform DataMosaix™ Private Cloud

CVE ID :CVE-2024-7953
Published : Sept. 1, 2026, 6:17 p.m. | 13 minutes ago
Description :A vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a threat actor could create, modify, and delete their own project.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 6:17 pm UTC

CVE-2026-84303 - gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

CVE ID :CVE-2026-84303
Published : Sept. 1, 2026, 6:14 p.m. | 16 minutes ago
Description :gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are lowercase. A DENY policy using a mixed-case name such as X-Role or User-Agent therefore does not match and fails open, allowing requests that should be rejected. The same case mismatch permits :Scheme or Grpc-Status to evade gRFC A41 validation and prevents Host from being rewritten to :authority. This issue is fixed in version 1.83.1.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 6:14 pm UTC

CVE-2026-83551 - Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK @step/@remote pipeline path

CVE ID :CVE-2026-83551
Published : Sept. 1, 2026, 6:11 p.m. | 19 minutes ago
Description :Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an authenticated remote user to extract the HMAC signing key from SageMaker DescribePipeline API responses and forge valid integrity signatures for specially crafted function payloads, achieving code execution in another user's pipeline execution context within the same AWS account.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 6:11 pm UTC

CVE-2026-8712 - Wyoming < 1.10.2 SSRF via uri Query Parameter

CVE ID :CVE-2026-8712
Published : Sept. 1, 2026, 6:09 p.m. | 21 minutes ago
Description :Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitrary targets by supplying a malicious `uri` query parameter to the HTTP API. Attackers can pass arbitrary `tcp://` or `unix://` URIs to affected endpoints including /api/info, /api/speech-to-text, and /api/text-to-speech to override the server-configured backend and redirect connections to attacker-chosen hosts.
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 6:09 pm UTC

CVE-2026-58566 - Dell PowerStore Incorrect Authorization Vulnerability

CVE ID :CVE-2026-58566
Published : Sept. 1, 2026, 5:17 p.m. | 1 hour, 13 minutes ago
Description :Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 5:17 pm UTC

CVE-2026-51956 - Grashjs Atlas CMMS Broken Object Level Authorization

CVE ID :CVE-2026-51956
Published : Sept. 1, 2026, 5:17 p.m. | 1 hour, 13 minutes ago
Description :A Broken Object Level Authorization vulnerability exists in Grashjs Atlas CMMS prior to v1.6.0. An authenticated user from one tenant can read and modify another tenant's company record by changing only the numeric ID in the /company/{id} endpoint. The application does not enforce tenant-level ownership checks when accessing or updating company objects, allowing cross-tenant access and modification of company profile data.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 5:17 pm UTC

CVE-2026-51934 - Tenda A18 Buffer Overflow Vulnerability

CVE ID :CVE-2026-51934
Published : Sept. 1, 2026, 5:17 p.m. | 1 hour, 13 minutes ago
Description :Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co., Ltd. Tenda A18 v.15.13.07.09 allows a remote attacker to execute arbitrary code via the fromSetCmdlineRun function
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 5:17 pm UTC

CVE-2026-51788 - Cleverange Auth Denial of Service Vulnerability

CVE ID :CVE-2026-51788
Published : Sept. 1, 2026, 5:17 p.m. | 1 hour, 13 minutes ago
Description :An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification function and the accounts/models.py component
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 5:17 pm UTC

CVE-2026-84269 - Gvfs: afp: heap-based buffer overflow in dsi read path

CVE ID :CVE-2026-84269
Published : Sept. 1, 2026, 4:17 p.m. | 2 hours, 13 minutes ago
Description :A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the intended boundaries. This issue allows a malicious server to overflow a heap buffer and crash the gvfsd-afp process, resulting in a denial of service.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 4:17 pm UTC

CVE-2026-84268 - Gvfs: sftp: heap-based buffer overflow in read_reply()

CVE ID :CVE-2026-84268
Published : Sept. 1, 2026, 4:17 p.m. | 2 hours, 13 minutes ago
Description :A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 4:17 pm UTC

CVE-2026-84267 - Gvfs: sftp: uninitialized heap disclosure in read_string()

CVE ID :CVE-2026-84267
Published : Sept. 1, 2026, 4:17 p.m. | 2 hours, 13 minutes ago
Description :A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer with a certain length but the function does not verify that the buffer is completely filled, leaving the remainder of the buffer containing uninitialized heap contents. If the server sends a short FXP_HANDLE reply, these uninitialized bytes are taken as the file handle. The client will then echo these uninitialized bytes back to the server on all subsequent requests using that handle. With a length of 128 bytes, this issue allows the malicious server to deterministically read uninitialized heap memory from the gvfsd-sftp process, leaking its heap base and the load address of the libgio library, resulting in a deterministic defeat of Address Space Layout Randomization (ASLR).
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 4:17 pm UTC

CVE-2026-84270 - Gvfs: mtp: out-of-bounds read in do_read()

CVE ID :CVE-2026-84270
Published : Sept. 1, 2026, 4:17 p.m. | 2 hours, 13 minutes ago
Description :A flaw was found in the MTP backend in gvfs. When reading a file from a mounted MTP device, do_read() in gvfsbackendmtp.c trusts the data length returned by the device without limiting it to the original size requested by the client. If a malicious MTP device responds with more bytes than requested, this unrestricted length is passed directly to memcpy(). This causes the operation to read memory outside the intended boundaries. This allows an attacker who plugs in a malicious MTP device to cause a segmentation fault when a file is read and crash the gvfsd-mtp process, resulting in a denial of service.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Sep 2026 | 4:17 pm UTC

ZDI-26-611: (0Day) pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

Source: ZDI: Published Advisories | 31 Aug 2026 | 5:00 am UTC

ZDI-26-614: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

Source: ZDI: Published Advisories | 31 Aug 2026 | 5:00 am UTC

ZDI-26-613: (0Day) pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

Source: ZDI: Published Advisories | 31 Aug 2026 | 5:00 am UTC

ZDI-26-615: (0Day) pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.

Source: ZDI: Published Advisories | 31 Aug 2026 | 5:00 am UTC

ZDI-26-612: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

Source: ZDI: Published Advisories | 31 Aug 2026 | 5:00 am UTC

ZDI-CAN-32191: NVIDIA

A CVSS score 8.0 AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Flydragon @ TRAPA Security' was reported to the affected vendor on: 2026-08-28, 4 days ago. The vendor is given until 2026-12-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 28 Aug 2026 | 5:00 am UTC

ZDI-CAN-32231: NVIDIA

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'YJK(@YJK0805) of ZUSO ART' was reported to the affected vendor on: 2026-08-28, 4 days ago. The vendor is given until 2026-12-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 28 Aug 2026 | 5:00 am UTC

ZDI-CAN-33973: Docker

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Nitesh Surana (niteshsurana.com) of TrendAI Research' was reported to the affected vendor on: 2026-08-28, 4 days ago. The vendor is given until 2026-12-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 28 Aug 2026 | 5:00 am UTC

ZDI-CAN-32895: Autodesk

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'ub1cu0' was reported to the affected vendor on: 2026-08-28, 4 days ago. The vendor is given until 2026-12-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 28 Aug 2026 | 5:00 am UTC

ZDI-CAN-32416: RAGFlow

A CVSS score 5.0 AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N severity vulnerability discovered by 'Connor Kastner (ret2c)' was reported to the affected vendor on: 2026-08-28, 4 days ago. The vendor is given until 2026-12-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 28 Aug 2026 | 5:00 am UTC

ZDI-CAN-33090: Philips

A CVSS score 3.8 AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N severity vulnerability discovered by 'Connor Ford @ByteInsight of TrendAI Zero Day Initiative' was reported to the affected vendor on: 2026-08-27, 5 days ago. The vendor is given until 2026-12-25 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 27 Aug 2026 | 5:00 am UTC

ZDI-CAN-33088: Philips

A CVSS score 4.3 AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N severity vulnerability discovered by 'Connor Ford @ByteInsight of TrendAI Zero Day Initiative' was reported to the affected vendor on: 2026-08-27, 5 days ago. The vendor is given until 2026-12-25 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 27 Aug 2026 | 5:00 am UTC

ZDI-CAN-31254: PostgreSQL

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Sajeeb Lohani' was reported to the affected vendor on: 2026-08-27, 5 days ago. The vendor is given until 2026-12-25 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 27 Aug 2026 | 5:00 am UTC

ZDI-CAN-32530: NVIDIA

A CVSS score 8.1 AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'YJK(@YJK0805) of ZUSO ART' was reported to the affected vendor on: 2026-08-26, 6 days ago. The vendor is given until 2026-12-24 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 26 Aug 2026 | 5:00 am UTC

ZDI-CAN-32376: Ultralytics

A CVSS score 8.8 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-08-26, 6 days ago. The vendor is given until 2026-12-24 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 26 Aug 2026 | 5:00 am UTC

ZDI-CAN-31013: VMware

A CVSS score 7.5 AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Stan S' was reported to the affected vendor on: 2026-08-26, 6 days ago. The vendor is given until 2026-12-24 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 26 Aug 2026 | 5:00 am UTC

ZDI-CAN-32601: PyTorch Foundation

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'YJK(@YJK0805) of ZUSO ART' was reported to the affected vendor on: 2026-08-26, 6 days ago. The vendor is given until 2026-12-24 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 26 Aug 2026 | 5:00 am UTC

ZDI-CAN-32822: LiteLLM

A CVSS score 5.0 AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N severity vulnerability discovered by 'NURIHAN KIM (HanTul)' was reported to the affected vendor on: 2026-08-26, 6 days ago. The vendor is given until 2026-12-24 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 26 Aug 2026 | 5:00 am UTC

ZDI-CAN-31929: Docker

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'chwrld (@chwrld24)' was reported to the affected vendor on: 2026-08-26, 6 days ago. The vendor is given until 2026-12-24 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 26 Aug 2026 | 5:00 am UTC

ZDI-CAN-32531: NVIDIA

A CVSS score 8.1 AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'YJK(@YJK0805) of ZUSO ART' was reported to the affected vendor on: 2026-08-26, 6 days ago. The vendor is given until 2026-12-24 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 26 Aug 2026 | 5:00 am UTC

ZDI-CAN-32834: PyTorch Foundation

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'YJK(@YJK0805) of ZUSO ART' was reported to the affected vendor on: 2026-08-26, 6 days ago. The vendor is given until 2026-12-24 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 26 Aug 2026 | 5:00 am UTC

ZDI-CAN-32710: LiteLLM

A CVSS score 5.3 AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N severity vulnerability discovered by 'Connor Kastner (ret2c)' was reported to the affected vendor on: 2026-08-26, 6 days ago. The vendor is given until 2026-12-24 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 26 Aug 2026 | 5:00 am UTC

ZDI-CAN-33087: Philips

A CVSS score 6.5 AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H severity vulnerability discovered by 'Connor Ford @ByteInsight of TrendAI Zero Day Initiative' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-31927: Samsung

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-29528: Net-SNMP

A CVSS score 7.2 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-33895: Net-SNMP

A CVSS score 7.2 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-32174: Linux

A CVSS score 7.8 AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'GangMin Kim' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-32092: FreeBSD

A CVSS score 7.5 AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'MICHAEL RANDRIANANTENAINA [https://elkamika.blogspot.com/]' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-31944: X.Org

A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-32353: Netgate

A CVSS score 8.8 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Alex Williams from Pellera Technologies' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-29529: Net-SNMP

A CVSS score 7.2 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-32366: X.Org

A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-32927: Linux

A CVSS score 7.8 AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Nico Yip (@_cyeaa_)' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-31834: X.Org

A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-31832: X.Org

A CVSS score 5.5 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-31221: X.Org

A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-33089: Philips

A CVSS score 8.0 AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Connor Ford @ByteInsight of TrendAI Zero Day Initiative' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-31833: X.Org

A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-33896: Net-SNMP

A CVSS score 7.2 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-31830: X.Org

A CVSS score 5.5 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-31941: X.Org

A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-32361: X.Org

A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-32836: Adobe

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-CAN-31938: X.Org

A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-08-25, 7 days ago. The vendor is given until 2026-12-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Aug 2026 | 5:00 am UTC

ZDI-26-593: NVIDIA TensorRT ONNX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA TensorRT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24268.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-588: Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Fabric.js. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 4.0. The following CVEs are assigned: CVE-2026-19504.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-610: Apple Safari JavaScriptCore B3 ReduceStrength Phase Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple Safari. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-64715.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-586: OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19886.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-601: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-13129.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-598: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-57242.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-600: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-57237.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-596: Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-57253.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-609: Linux Kernel Net Scheduler Packet Classifier Use-After-Free Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-587: Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19781.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-589: BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2026-19774.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-591: NVIDIA TensorRT ONNX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA TensorRT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24272.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-590: libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of libwebsockets. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-19773.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-592: NVIDIA TensorRT ONNX File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA TensorRT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24238.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-606: Microsoft Windows Compatibility Appraiser Link Following Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code in the context of LOCAL SERVICE on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-604: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13126.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-608: Linux Kernel KVM IOAPIC Use-After-Free Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-607: Microsoft Office HTML Injection Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Office. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.6.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-595: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-57254.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-602: Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13128.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-594: NVIDIA Megatron Bridge load_model_config Code Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Megatron Bridge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24251.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-597: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-57252.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-605: Microsoft Windows Localized Filenames Improper Input Validation NTLM Response Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose NTLM responses on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-50508.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-585: OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19885.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-603: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13127.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-26-599: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-57238.

Source: ZDI: Published Advisories | 24 Aug 2026 | 5:00 am UTC

ZDI-CAN-32508: Autodesk

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Liang Zhu' was reported to the affected vendor on: 2026-08-21, 11 days ago. The vendor is given until 2026-12-19 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 21 Aug 2026 | 5:00 am UTC

ZDI-CAN-32513: Autodesk

A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by 'Liang Zhu' was reported to the affected vendor on: 2026-08-21, 11 days ago. The vendor is given until 2026-12-19 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 21 Aug 2026 | 5:00 am UTC

ZDI-CAN-32177: Autodesk

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Liang Zhu' was reported to the affected vendor on: 2026-08-21, 11 days ago. The vendor is given until 2026-12-19 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 21 Aug 2026 | 5:00 am UTC

ZDI-CAN-32454: Foxit

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'praydog & kmx00' was reported to the affected vendor on: 2026-08-20, 12 days ago. The vendor is given until 2026-12-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 20 Aug 2026 | 5:00 am UTC

ZDI-CAN-32356: FreeBSD

A CVSS score 7.8 AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'tsune of GMO Cybersecurity by Ierae, Inc.' was reported to the affected vendor on: 2026-08-20, 12 days ago. The vendor is given until 2026-12-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 20 Aug 2026 | 5:00 am UTC

count: 100