jell.ie CVEs

Read at: 2026-07-14T07:39:11+00:00

CVE-2026-15668 - louisho5 picobot web Tool web.go WebTool.Execute server-side request forgery

CVE ID :CVE-2026-15668
Published : July 14, 2026, 5:16 a.m. | 26 minutes ago
Description :A vulnerability has been found in louisho5 picobot up to 0.2.0. This vulnerability affects the function WebTool.Execute of the file internal/agent/tools/web.go of the component web Tool. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 5:16 am UTC

CVE-2026-15629 - louisho5 picobot Workspace filesystem.go GetSkill link following

CVE ID :CVE-2026-15629
Published : July 14, 2026, 5:16 a.m. | 26 minutes ago
Description :A weakness has been identified in louisho5 picobot up to 0.2.0. Impacted is the function CreateSkill/GetSkill of the file internal/agent/tools/filesystem.go of the component Workspace Handler. Executing a manipulation can lead to link following. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 5:16 am UTC

CVE-2026-15669 - louisho5 picobot exec Tool exec.go ExecTool.Execute os command injection

CVE ID :CVE-2026-15669
Published : July 14, 2026, 5:15 a.m. | 27 minutes ago
Description :A vulnerability was found in louisho5 picobot up to 0.2.0. This issue affects the function ExecTool.Execute of the file internal/agent/tools/exec.go of the component exec Tool. The manipulation results in os command injection. The attack requires a local approach. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 5:15 am UTC

CVE-2026-12482 - Path Traversal via Symlink Name Validation Bypass in keras-team/keras

CVE ID :CVE-2026-12482
Published : July 14, 2026, 5:13 a.m. | 29 minutes ago
Description :A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` validation in `keras/src/utils/file_utils.py`. Specifically, symlink entries are not subjected to the same `is_path_in_dir` validation as regular file entries, allowing symlinks to be created outside the intended extraction directory. This can lead to symlink-based file read, file overwrite, or directory escape attacks. The issue is particularly impactful on Python 3.10 and 3.11, where `filter_safe_tarinfos` is the sole defense against tar path traversal. This vulnerability is distinct from CVE-2025-12060 and other previously reported issues.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 5:13 am UTC

CVE-2026-15628 - zhayujie chatgpt-on-wechat CowAgent Vision Tool vision.py Vision._download_to_data_url server-side request forgery

CVE ID :CVE-2026-15628
Published : July 14, 2026, 4:17 a.m. | 1 hour, 25 minutes ago
Description :A security flaw has been discovered in zhayujie chatgpt-on-wechat CowAgent up to 2.1.1. This issue affects the function Vision._download_to_data_url of the file agent/tools/vision/vision.py of the component Vision Tool. Performing a manipulation of the argument image results in server-side request forgery. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.1.2 is capable of addressing this issue. The patch is named e85290cddcbb5ffc9c235927f4c92e5b4c3ec264. The affected component should be upgraded.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 4:17 am UTC

CVE-2026-15627 - nextlevelbuilder GoClaw tool.go handleNavigate information disclosure

CVE ID :CVE-2026-15627
Published : July 14, 2026, 4:17 a.m. | 1 hour, 25 minutes ago
Description :A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This vulnerability affects the function handleNavigate of the file pkg/browser/tool.go. Such manipulation of the argument args.targetUrl leads to information disclosure. The attack may be performed from remote. The exploit is publicly available and might be used.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 4:17 am UTC

CVE-2026-15626 - nextlevelbuilder GoClaw ACP ToolBridge Workspace tool_bridge.go writeFile path traversal

CVE ID :CVE-2026-15626
Published : July 14, 2026, 4:17 a.m. | 1 hour, 25 minutes ago
Description :A vulnerability was determined in nextlevelbuilder GoClaw 3.13.3-beta.3. This affects the function writeFile of the file internal/providers/acp/tool_bridge.go of the component ACP ToolBridge Workspace Handler. This manipulation causes path traversal. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 4:17 am UTC

CVE-2026-7640 - WP Customer Area <= 8.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'type' Shortcode Attribute

CVE ID :CVE-2026-7640
Published : July 14, 2026, 2:16 a.m. | 3 hours, 25 minutes ago
Description :The WP Customer Area plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the `customer-area-protected-content` shortcode in all versions up to, and including, 8.3.5. This is due to insufficient input sanitization and output escaping on the shortcode attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 2:16 am UTC

CVE-2026-15622 - poco-ai poco-claw Workspace API workspace.py get_workspace_file authorization

CVE ID :CVE-2026-15622
Published : July 14, 2026, 2:16 a.m. | 3 hours, 25 minutes ago
Description :A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor_manager/app/api/v1/workspace.py of the component Workspace API. Executing a manipulation of the argument user_id can lead to authorization bypass. The attack may be launched remotely. The exploit has been published and may be used. This patch is called 67fcc88505c57f77d3fcf04eb5b89425b10cbf48. Upgrading the affected component is recommended.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 2:16 am UTC

CVE-2026-15625 - nextlevelbuilder GoClaw exec_approval.go ExecApprovalManager.CheckCommand incomplete blacklist

CVE ID :CVE-2026-15625
Published : July 14, 2026, 2:16 a.m. | 3 hours, 25 minutes ago
Description :A vulnerability was found in nextlevelbuilder GoClaw 3.11.3. Affected by this issue is the function ExecApprovalManager.CheckCommand of the file internal/tools/exec_approval.go. The manipulation results in incomplete blacklist. The attack can be executed remotely. The exploit has been made public and could be used.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 2:16 am UTC

CVE-2026-15624 - nextlevelbuilder GoClaw invoke Endpoint create_video_byteplus.go bytePlusDownloadVideo server-side request forgery

CVE ID :CVE-2026-15624
Published : July 14, 2026, 2:16 a.m. | 3 hours, 25 minutes ago
Description :A vulnerability has been found in nextlevelbuilder GoClaw 3.13.3-beta.3. Affected by this vulnerability is the function bytePlusDownloadVideo of the file internal/tools/create_video_byteplus.go of the component invoke Endpoint. The manipulation of the argument output.video_url leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 2:16 am UTC

CVE-2026-11390 - News Kit Addons For Elementor <= 1.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets

CVE ID :CVE-2026-11390
Published : July 14, 2026, 2:16 a.m. | 3 hours, 25 minutes ago
Description :The News Kit Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an attacker to intercept and modify the elementor_ajax AJAX save request in order to bypass the client-side SELECT control restrictions and submit arbitrary tag-name values.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 2:16 am UTC

CVE-2026-11802 - FoodBook Lite <= 1.5.6 - Missing Authorization to Unauthenticated User Registration via 'registration_action' AJAX Action

CVE ID :CVE-2026-11802
Published : July 14, 2026, 2:16 a.m. | 3 hours, 25 minutes ago
Description :The FoodBook Lite - Online Food Ordering System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5.6. The registration() function, accessible via the wp_ajax_nopriv_registration_action AJAX action, lacks any nonce verification or capability check, and does not check the WordPress users_can_register option before calling wp_insert_user(). This makes it possible for unauthenticated attackers to create new user accounts with the 'customer' role and receive authentication cookies, even when the site administrator has explicitly disabled user registration.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 2:16 am UTC

CVE-2026-44761 - Insecure Sample Credentials in SAP Commerce Cloud

CVE ID :CVE-2026-44761
Published : July 14, 2026, 1:16 a.m. | 4 hours, 26 minutes ago
Description :SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 1:16 am UTC

CVE-2026-44768 - Security misconfiguration in SAP CRM (WebClient UI)

CVE ID :CVE-2026-44768
Published : July 14, 2026, 1:16 a.m. | 4 hours, 26 minutes ago
Description :SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to the absence of a Content Security Policy (CSP) configuration for certain restrictive directives. This vulnerability has a low impact on the integrity of the application. Confidentiality and availability are not impacted.
Severity: 4.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 1:16 am UTC

CVE-2026-44770 - Missing Authorization check in SAP S/4 HANA (Create Single Payment)

CVE ID :CVE-2026-44770
Published : July 14, 2026, 1:16 a.m. | 4 hours, 26 minutes ago
Description :SAP Create Single Payment does not perform necessary authorization checks for an authenticated user, a restricted user could access specific entity set keys resulting in disclosure of information. This has low impact on confidentiality, with no impact on integrity and availability of the application.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 1:16 am UTC

CVE-2026-44771 - Missing Authorization check in SAP S/4HANA (Draft operation)

CVE ID :CVE-2026-44771
Published : July 14, 2026, 1:16 a.m. | 4 hours, 26 minutes ago
Description :SAP S/4HANA Draft operation does not perform necessary authorization checks for an authenticated user, a restricted user could access information within the entity resulting in escalation of privileges. This results in low impact on confidentiality, with no impact on integrity and availability of the application.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 1:16 am UTC

CVE-2026-58233 - Remote Code Execution vulnerability in SAP Change and Transport System Attach Tool (ctsattach)

CVE ID :CVE-2026-58233
Published : July 14, 2026, 1:16 a.m. | 4 hours, 26 minutes ago
Description :SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system. Successful exploitation requires a victim to process the malicious archive, enabling the attacker to execute the RCE and extract sensitive information and gain control over the system and its processes. This vulnerability has a high impact on confidentiality and integrity of the data, with a low impact on the availability of the system.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 1:16 am UTC

CVE-2026-44767 - Allowlist Bypass in setThemeRoot() Enables Cross-Origin CSS Injection

CVE ID :CVE-2026-44767
Published : July 14, 2026, 1:16 a.m. | 4 hours, 26 minutes ago
Description :setThemeRoot() failed to enforce the sap-allowed-theme-origins allowlist. An attacker-controlled absolute cross-origin URL could be stored and used directly to construct a element, even when no tag was present in the document. The same bypass was reachable via the ?sap-themeRoot URL parameter.Exploitation requires attacker-influenced input (e.g., a URL query parameter, tenant configuration, or user-supplied setting) to reach setThemeRoot(). A successful exploit allows an attacker to inject arbitrary CSS into the victim page, enabling:- UI redressing and clickjacking- Phishing overlays- Visual defacement- Limited data exfiltration via CSS attribute selectors targeting predictable DOM content
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 1:16 am UTC

CVE-2026-44769 - SQL Injection vulnerability in SAP S/4HANA Project Management (PPM-PRO)

CVE ID :CVE-2026-44769
Published : July 14, 2026, 1:16 a.m. | 4 hours, 26 minutes ago
Description :SAP S/4HANA application Project Management (PPM-PRO) allows an attacker with high privileges to execute crafted database queries, exposing the backend database. This results in low impact on confidentiality, with no impact on integrity and availability of the application.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 1:16 am UTC

CVE-2026-44759 - Cross Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

CVE ID :CVE-2026-44759
Published : July 14, 2026, 1:16 a.m. | 4 hours, 26 minutes ago
Description :SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal content, or user redirection, resulting in a low impact on the application's confidentiality and integrity, with no impact on availability.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 1:16 am UTC

CVE-2026-44760 - Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications based on Business Server Pages)

CVE ID :CVE-2026-44760
Published : July 14, 2026, 1:16 a.m. | 4 hours, 26 minutes ago
Description :Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SAP NetWeaver Application Server ABAP reflects unsanitized input into the HTTP response which allows an attacker to inject and execute arbitrary JavaScript code under certain conditions. Successful exploitation could allow the attacker to steal session information, perform authenticated actions on behalf of the victim user etc. This vulnerability has low impact on confidentiality and integrity of the data and no impact on application 's availability.
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 1:16 am UTC

CVE-2026-44753 - Information Disclosure vulnerability in SAP HANA Extended Application Services classic model (User Self Service)

CVE ID :CVE-2026-44753
Published : July 14, 2026, 1:16 a.m. | 4 hours, 26 minutes ago
Description :SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation could allow the attacker to enumerate valid user accounts, resulting in low impact on confidentiality, with no impact on integrity and availability of the application.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 1:16 am UTC

CVE-2026-44752 - Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java(Configuration Wizard)

CVE ID :CVE-2026-44752
Published : July 14, 2026, 1:16 a.m. | 4 hours, 26 minutes ago
Description :SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user's browser, allowing the attacker to access sensitive session information and modify non-sensitive data displayed in the client�s browser. This results in a high impact on confidentiality, low impact on integrity with no impact on availability of the application.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 1:16 am UTC

CVE-2026-44747 - Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP

CVE ID :CVE-2026-44747
Published : July 14, 2026, 1:16 a.m. | 4 hours, 26 minutes ago
Description :SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the application.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 14 Jul 2026 | 1:16 am UTC

ZDI-26-400: (0Day) AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability

This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.7. The following CVEs are assigned: CVE-2026-15681.

Source: ZDI: Published Advisories | 13 Jul 2026 | 5:00 am UTC

ZDI-CAN-32560: deepset

A CVSS score 9.3 AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N severity vulnerability discovered by 'Taha Siddiqi (@_atomiz_) of TrendAI Research' was reported to the affected vendor on: 2026-07-10, 4 days ago. The vendor is given until 2026-11-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 10 Jul 2026 | 5:00 am UTC

ZDI-CAN-32105: NVIDIA

A CVSS score 9.3 AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N severity vulnerability discovered by 'Habibullo Izzatilloyev' was reported to the affected vendor on: 2026-07-10, 4 days ago. The vendor is given until 2026-11-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 10 Jul 2026 | 5:00 am UTC

ZDI-CAN-32156: NVIDIA

A CVSS score 8.1 AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Flydragon @ TRAPA Security' was reported to the affected vendor on: 2026-07-10, 4 days ago. The vendor is given until 2026-11-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 10 Jul 2026 | 5:00 am UTC

ZDI-CAN-32609: deepset

A CVSS score 5.9 AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N severity vulnerability discovered by 'Minh Giang (@itscysamu) of TrendAI Zero Day Initiative and Taha Siddiqi (@_atomiz_) of TrendAI Research' was reported to the affected vendor on: 2026-07-10, 4 days ago. The vendor is given until 2026-11-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 10 Jul 2026 | 5:00 am UTC

ZDI-CAN-32106: NVIDIA

A CVSS score 9.3 AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N severity vulnerability discovered by 'Habibullo Izzatilloyev' was reported to the affected vendor on: 2026-07-10, 4 days ago. The vendor is given until 2026-11-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 10 Jul 2026 | 5:00 am UTC

ZDI-CAN-30184: Oracle

A CVSS score 7.5 AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Phan Vinh Khang of Viettel Cyber Security' was reported to the affected vendor on: 2026-07-10, 4 days ago. The vendor is given until 2026-11-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 10 Jul 2026 | 5:00 am UTC

ZDI-CAN-31118: Quest

A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Bobby Gould (@bobbygould5) of TrendAI Zero Day Initiative' was reported to the affected vendor on: 2026-07-10, 4 days ago. The vendor is given until 2026-11-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 10 Jul 2026 | 5:00 am UTC

ZDI-CAN-29835: Oracle

A CVSS score 6.1 AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L severity vulnerability discovered by 'Xiaobye(@xiaobye_tw) of DEVCORE Research Team' was reported to the affected vendor on: 2026-07-10, 4 days ago. The vendor is given until 2026-11-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 10 Jul 2026 | 5:00 am UTC

ZDI-CAN-32581: Senstar

A CVSS score 7.2 AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N severity vulnerability discovered by 'Minh Giang (@itscysamu) of TrendAI Zero Day Initiative' was reported to the affected vendor on: 2026-07-10, 4 days ago. The vendor is given until 2026-11-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 10 Jul 2026 | 5:00 am UTC

ZDI-CAN-31096: LibreOffice

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-07-09, 5 days ago. The vendor is given until 2026-11-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 9 Jul 2026 | 5:00 am UTC

ZDI-CAN-31095: LibreOffice

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-07-09, 5 days ago. The vendor is given until 2026-11-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 9 Jul 2026 | 5:00 am UTC

ZDI-CAN-31734: ABRT

A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Ryota Shiga (GMO Flatt Security Inc.)' was reported to the affected vendor on: 2026-07-09, 5 days ago. The vendor is given until 2026-11-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 9 Jul 2026 | 5:00 am UTC

ZDI-CAN-31097: LibreOffice

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-07-09, 5 days ago. The vendor is given until 2026-11-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 9 Jul 2026 | 5:00 am UTC

ZDI-CAN-31076: LibreOffice

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-07-09, 5 days ago. The vendor is given until 2026-11-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 9 Jul 2026 | 5:00 am UTC

ZDI-26-402: (0Day) Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Glarysoft Glary Utilities. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2026-15684.

Source: ZDI: Published Advisories | 8 Jul 2026 | 5:00 am UTC

ZDI-26-399: (0Day) (Pwn2Own) Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lorex 2K Indoor Wi-Fi Security Cameras. User interaction is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-15683.

Source: ZDI: Published Advisories | 8 Jul 2026 | 5:00 am UTC

ZDI-26-401: (0Day) AnyDesk Support Information Link Following Denial-of-Service Vulnerability

This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.7. The following CVEs are assigned: CVE-2026-15682.

Source: ZDI: Published Advisories | 8 Jul 2026 | 5:00 am UTC

ZDI-26-398: (0Day) (Pwn2Own) Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lorex 2K Indoor Wi-Fi Security Cameras. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-15680.

Source: ZDI: Published Advisories | 8 Jul 2026 | 5:00 am UTC

ZDI-26-403: (0Day) Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-15685.

Source: ZDI: Published Advisories | 8 Jul 2026 | 5:00 am UTC

ZDI-CAN-31739: Linux

A CVSS score 7.8 AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'YingMuo (@YingMuo) of DEVCORE Research Team' was reported to the affected vendor on: 2026-07-07, 7 days ago. The vendor is given until 2026-11-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 7 Jul 2026 | 5:00 am UTC

ZDI-CAN-31451: VMware

A CVSS score 8.8 AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Gwangun Jung (@pr0ln) of Theori, with Xint Code' was reported to the affected vendor on: 2026-07-07, 7 days ago. The vendor is given until 2026-11-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 7 Jul 2026 | 5:00 am UTC

ZDI-CAN-31121: Oracle

A CVSS score 7.5 AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Xiaobye(@xiaobye_tw) of DEVCORE Research Team' was reported to the affected vendor on: 2026-07-07, 7 days ago. The vendor is given until 2026-11-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 7 Jul 2026 | 5:00 am UTC

ZDI-CAN-31014: oFono

A CVSS score 8.4 AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-07-03, 11 days ago. The vendor is given until 2026-10-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Jul 2026 | 5:00 am UTC

ZDI-CAN-31764: Linux

A CVSS score 7.8 AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Nico Yip (@_cyeaa_)' was reported to the affected vendor on: 2026-07-03, 11 days ago. The vendor is given until 2026-10-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Jul 2026 | 5:00 am UTC

ZDI-CAN-31149: Linux

A CVSS score 7.5 AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-07-03, 11 days ago. The vendor is given until 2026-10-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Jul 2026 | 5:00 am UTC

ZDI-CAN-31610: Linux

A CVSS score 7.8 AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-07-03, 11 days ago. The vendor is given until 2026-10-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Jul 2026 | 5:00 am UTC

ZDI-CAN-31063: Linux

A CVSS score 9.3 AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L severity vulnerability discovered by 'p2gone' was reported to the affected vendor on: 2026-07-03, 11 days ago. The vendor is given until 2026-10-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Jul 2026 | 5:00 am UTC

ZDI-CAN-31523: Linux

A CVSS score 7.5 AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'elden, Brayn Mbeumo' was reported to the affected vendor on: 2026-07-03, 11 days ago. The vendor is given until 2026-10-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Jul 2026 | 5:00 am UTC

ZDI-CAN-30609: LibreOffice

A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-07-03, 11 days ago. The vendor is given until 2026-10-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Jul 2026 | 5:00 am UTC

ZDI-CAN-30656: Microsoft

A CVSS score 8.8 AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-07-03, 11 days ago. The vendor is given until 2026-10-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Jul 2026 | 5:00 am UTC

ZDI-CAN-31036: libwebsockets

A CVSS score 9.8 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Maher Azzouzi' was reported to the affected vendor on: 2026-07-03, 11 days ago. The vendor is given until 2026-10-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Jul 2026 | 5:00 am UTC

ZDI-CAN-30625: Langflow

A CVSS score 9.8 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Nicholas Zubrisky (@NZubrisky) of TrendAI Zero Day Initiative' was reported to the affected vendor on: 2026-07-03, 11 days ago. The vendor is given until 2026-10-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Jul 2026 | 5:00 am UTC

ZDI-CAN-31151: LibreOffice

A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'truff' was reported to the affected vendor on: 2026-07-03, 11 days ago. The vendor is given until 2026-10-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Jul 2026 | 5:00 am UTC

ZDI-CAN-31075: LibreOffice

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-07-03, 11 days ago. The vendor is given until 2026-10-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Jul 2026 | 5:00 am UTC

ZDI-CAN-31604: Linux

A CVSS score 7.8 AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-07-03, 11 days ago. The vendor is given until 2026-10-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Jul 2026 | 5:00 am UTC

ZDI-CAN-31517: Linux

A CVSS score 7.8 AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-07-03, 11 days ago. The vendor is given until 2026-10-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Jul 2026 | 5:00 am UTC

ZDI-CAN-28837: Hinemos

A CVSS score 7.5 AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'hrk' was reported to the affected vendor on: 2026-07-02, 12 days ago. The vendor is given until 2026-10-30 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 2 Jul 2026 | 5:00 am UTC

ZDI-CAN-31374: Adobe

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-06-30, 14 days ago. The vendor is given until 2026-10-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 30 Jun 2026 | 5:00 am UTC

ZDI-CAN-29955: NI

A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by 'Grigory Dorodnov of TrendAI Research' was reported to the affected vendor on: 2026-06-30, 14 days ago. The vendor is given until 2026-10-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 30 Jun 2026 | 5:00 am UTC

ZDI-CAN-31386: Adobe

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-06-30, 14 days ago. The vendor is given until 2026-10-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 30 Jun 2026 | 5:00 am UTC

ZDI-CAN-31895: MLflow

A CVSS score 7.7 AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N severity vulnerability discovered by 's3zer0' was reported to the affected vendor on: 2026-06-30, 14 days ago. The vendor is given until 2026-10-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 30 Jun 2026 | 5:00 am UTC

ZDI-CAN-30998: Adobe

A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-06-30, 14 days ago. The vendor is given until 2026-10-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 30 Jun 2026 | 5:00 am UTC

ZDI-CAN-32107: MLflow

A CVSS score 6.3 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L severity vulnerability discovered by 'Grigory Dorodnov of TrendAI Research' was reported to the affected vendor on: 2026-06-30, 14 days ago. The vendor is given until 2026-10-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 30 Jun 2026 | 5:00 am UTC

ZDI-CAN-31150: Adobe

A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by 'NURIHAN KIM (HanTul)' was reported to the affected vendor on: 2026-06-30, 14 days ago. The vendor is given until 2026-10-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 30 Jun 2026 | 5:00 am UTC

ZDI-CAN-29954: NI

A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by 'Grigory Dorodnov of TrendAI Research' was reported to the affected vendor on: 2026-06-30, 14 days ago. The vendor is given until 2026-10-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 30 Jun 2026 | 5:00 am UTC

ZDI-CAN-32169: Oracle

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Mat Powell of TrendAI Zero Day Initiative' was reported to the affected vendor on: 2026-06-30, 14 days ago. The vendor is given until 2026-10-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 30 Jun 2026 | 5:00 am UTC

ZDI-CAN-31369: Cisco

A CVSS score 8.1 AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by '@TristanInSec' was reported to the affected vendor on: 2026-06-30, 14 days ago. The vendor is given until 2026-10-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 30 Jun 2026 | 5:00 am UTC

ZDI-CAN-32108: MLflow

A CVSS score 5.4 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N severity vulnerability discovered by 'Grigory Dorodnov of TrendAI Research' was reported to the affected vendor on: 2026-06-30, 14 days ago. The vendor is given until 2026-10-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 30 Jun 2026 | 5:00 am UTC

ZDI-CAN-31897: Langflow

A CVSS score 5.0 AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-06-30, 14 days ago. The vendor is given until 2026-10-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 30 Jun 2026 | 5:00 am UTC

ZDI-CAN-31794: pdfforge

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'chwrld (@chwrld24)' was reported to the affected vendor on: 2026-06-30, 14 days ago. The vendor is given until 2026-10-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 30 Jun 2026 | 5:00 am UTC

ZDI-CAN-29934: Quest

A CVSS score 8.2 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L severity vulnerability discovered by '06fe5fd2bc53027c4a3b7e395af0b850e7b8a044' was reported to the affected vendor on: 2026-06-26, 18 days ago. The vendor is given until 2026-10-24 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 26 Jun 2026 | 5:00 am UTC

ZDI-CAN-32027: Adobe

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Brandon Evans of TrendAI Zero Day Initiative' was reported to the affected vendor on: 2026-06-26, 18 days ago. The vendor is given until 2026-10-24 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 26 Jun 2026 | 5:00 am UTC

ZDI-CAN-32110: RAGFlow

A CVSS score 6.3 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L severity vulnerability discovered by 'Taha Siddiqi (@_atomiz_) of TrendAI Research' was reported to the affected vendor on: 2026-06-26, 18 days ago. The vendor is given until 2026-10-24 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 26 Jun 2026 | 5:00 am UTC

ZDI-CAN-32109: RAGFlow

A CVSS score 7.3 AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L severity vulnerability discovered by 'Taha Siddiqi (@_atomiz_) of TrendAI Research' was reported to the affected vendor on: 2026-06-26, 18 days ago. The vendor is given until 2026-10-24 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 26 Jun 2026 | 5:00 am UTC

ZDI-CAN-31973: Adobe

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Brandon Evans of TrendAI Zero Day Initiative' was reported to the affected vendor on: 2026-06-26, 18 days ago. The vendor is given until 2026-10-24 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 26 Jun 2026 | 5:00 am UTC

ZDI-CAN-31152: LibreOffice

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'truff' was reported to the affected vendor on: 2026-06-26, 18 days ago. The vendor is given until 2026-10-24 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 26 Jun 2026 | 5:00 am UTC

ZDI-CAN-32111: RAGFlow

A CVSS score 8.8 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Taha Siddiqi (@_atomiz_) of TrendAI Research' was reported to the affected vendor on: 2026-06-26, 18 days ago. The vendor is given until 2026-10-24 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 26 Jun 2026 | 5:00 am UTC

ZDI-CAN-30087: Wibu-Systems

A CVSS score 3.8 AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N severity vulnerability discovered by 'haro001' was reported to the affected vendor on: 2026-06-26, 18 days ago. The vendor is given until 2026-10-24 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 26 Jun 2026 | 5:00 am UTC

ZDI-CAN-32112: RAGFlow

A CVSS score 6.3 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L severity vulnerability discovered by 'Taha Siddiqi (@_atomiz_) of TrendAI Research' was reported to the affected vendor on: 2026-06-26, 18 days ago. The vendor is given until 2026-10-24 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 26 Jun 2026 | 5:00 am UTC

ZDI-CAN-30236: Samsung

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Michael DePlante (@izobashi) of TrendAI Zero Day Initiative' was reported to the affected vendor on: 2026-06-26, 18 days ago. The vendor is given until 2026-10-24 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 26 Jun 2026 | 5:00 am UTC

ZDI-CAN-32035: Apache

A CVSS score 5.8 AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L severity vulnerability discovered by 'Minh Giang (@itscysamu) and Nicholas Zubrisky (@NZubrisky) of TrendAI Zero Day Initiative' was reported to the affected vendor on: 2026-06-25, 19 days ago. The vendor is given until 2026-10-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Jun 2026 | 5:00 am UTC

ZDI-CAN-29751: Oracle

A CVSS score 7.5 AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Team Amazone@229' was reported to the affected vendor on: 2026-06-25, 19 days ago. The vendor is given until 2026-10-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Jun 2026 | 5:00 am UTC

ZDI-CAN-31419: Linux

A CVSS score 7.5 AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by '@TristanInSec' was reported to the affected vendor on: 2026-06-25, 19 days ago. The vendor is given until 2026-10-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Jun 2026 | 5:00 am UTC

ZDI-CAN-31417: Linux

A CVSS score 7.5 AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'GangMin Kim' was reported to the affected vendor on: 2026-06-25, 19 days ago. The vendor is given until 2026-10-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Jun 2026 | 5:00 am UTC

ZDI-CAN-31133: Linux

A CVSS score 8.2 AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Mark H' was reported to the affected vendor on: 2026-06-25, 19 days ago. The vendor is given until 2026-10-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Jun 2026 | 5:00 am UTC

ZDI-CAN-31139: Linux

A CVSS score 8.2 AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Eldudareeno' was reported to the affected vendor on: 2026-06-25, 19 days ago. The vendor is given until 2026-10-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Jun 2026 | 5:00 am UTC

ZDI-CAN-30083: Oracle

A CVSS score 7.5 AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'crixer(@pwning_me)' was reported to the affected vendor on: 2026-06-25, 19 days ago. The vendor is given until 2026-10-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Jun 2026 | 5:00 am UTC

ZDI-CAN-31527: Linux

A CVSS score 8.8 AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Sajeeb Lohani' was reported to the affected vendor on: 2026-06-25, 19 days ago. The vendor is given until 2026-10-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Jun 2026 | 5:00 am UTC

ZDI-CAN-31587: OriginLab

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'chwrld (@chwrld24)' was reported to the affected vendor on: 2026-06-24, 20 days ago. The vendor is given until 2026-10-22 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 24 Jun 2026 | 5:00 am UTC

ZDI-CAN-32004: Microsoft

A CVSS score 4.3 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N severity vulnerability discovered by 'Nitesh Surana (niteshsurana.com) of TrendAI Research' was reported to the affected vendor on: 2026-06-24, 20 days ago. The vendor is given until 2026-10-22 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 24 Jun 2026 | 5:00 am UTC

ZDI-26-395: X.Org Server SyncChangeCounter Use-After-Free Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-50261.

Source: ZDI: Published Advisories | 24 Jun 2026 | 5:00 am UTC

ZDI-26-374: Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-9785.

Source: ZDI: Published Advisories | 24 Jun 2026 | 5:00 am UTC

ZDI-26-388: Oracle PeopleSoft HubMBeanPersistance Deserialization of Untrusted Data Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle PeopleSoft. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-35273.

Source: ZDI: Published Advisories | 24 Jun 2026 | 5:00 am UTC

ZDI-26-361: Adobe Acrobat Reader DC Field signatureInfo Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-27278.

Source: ZDI: Published Advisories | 24 Jun 2026 | 5:00 am UTC

count: 100