jell.ie CVEs

Read at: 2026-10-01T22:25:33+00:00

CVE-2026-102370 - Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71

CVE ID :CVE-2026-102370
Published : Oct. 1, 2026, 8:47 p.m. | 19 minutes ago
Description :Kasa EC70 v4 and EC71 v4 do not logically disable the production debug interface at the firmware or chip level and do not lock the bootloader.  Although the debug traces are physically severed during manufacturing, an attacker with physical access can restore the connection, interrupt the boot process, and manipulate boot parameters to enter a non-standard initialization path that exposes an unauthenticated root shell during startup. Successful exploitation may allow an attacker with physical access to obtain root-level command access during device startup, resulting in loss of confidentiality, integrity, and availability for the affected device. Exploitation requires device disassembly, restoration of the severed debug connection, and manipulation of the boot process.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:47 pm UTC

CVE-2026-104020 - Uncontrolled recursion in the Ion reader in Amazon Ion Python

CVE ID :CVE-2026-104020
Published : Oct. 1, 2026, 8:36 p.m. | 30 minutes ago
Description :Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value. To remediate this issue, users should upgrade to version 0.15.0 or later.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:36 pm UTC

CVE-2026-96780 - figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width

CVE ID :CVE-2026-96780
Published : Oct. 1, 2026, 8:21 p.m. | 45 minutes ago
Description :figlet.js is a FIG driver written in JavaScript that aims to implement the FIGfont specification. Prior to 1.11.3, text() and textSync() can enter an unbounded loop when whitespaceBreak is enabled and width is smaller than the rendered width of a single FIGlet character. Under these conditions, breakWord() cannot find a valid break point and returns without consuming a character, so generateFigTextLines() repeatedly processes the same input while consuming CPU and growing memory. The non-default option and attacker-controlled width must both reach an affected call. This issue is fixed in version 1.11.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:21 pm UTC

CVE-2026-93832 - Motorola System Application Unauthorized Permission Revocation Vulnerability

CVE ID :CVE-2026-93832
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :A component of one of the Motorola system applications was exported without permission, allowing for the revocation of runtime permissions from other apps.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-82358 - RT-Labs AB C-Open CANopen SDO Server Write Protection Bypass

CVE ID :CVE-2026-82358
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object) server implementation 'src/co_sdo_server.c' that fails to properly validate write permissions when processing download-segment frames. An unauthenticated attacker on the CAN bus can initiate an SDO upload for a read-only Object Dictionary (OD) entry, which sets a data pointer to the read-only object, then send download-segment frames to write to that memory location. The download-segment handler does not verify that a download session is active, allowing any CANopen node to overwrite read-only OD entries using two SDO frames. Note that CANopen protocol operates over CAN bus and does not provide built-in authentication mechanisms. Fixed in 1.1.1.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-82357 - RT-Labs AB C-Open CANopen NULL pointer dereference

CVE ID :CVE-2026-82357
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS protocol is used to configure the device. An object defined by the user application may not have all required subindexes for object 0x1018. An unauthenticated, remote attacker with access to the CAN bus, through a compromised node for instance, can initiate the LSS protocol on a device with a misconfigured identity object and potentially crash the device. Fixed in 1.1.1.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-71542 - GetSimple CMS: Stored Cross-Site Scripting (XSS) via the "title" parameter in admin/components.php

CVE ID :CVE-2026-71542
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, GetSimpleCMS-CE is vulnerable to stored Cross-Site Scripting (XSS) in the "Theme to Components" functionality (admin/components.php) via the title parameter. The stored title is rendered inside a double-quoted HTML attribute in the administrative interface through an output path that HTML-entity-decodes the value before printing it, without re-encoding for the attribute context. This allows persistent execution of arbitrary JavaScript in the admin panel. At time of publication, there are no publicly available patches.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-71426 - GetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page "template" field

CVE ID :CVE-2026-71426
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated user with page-editing rights can store an arbitrary filesystem path in a page's template attribute. On the public front-end, this value is passed unsanitized to a PHP include() when the page is rendered. Because the include path is never confined, this allows directory-traversal Local File Inclusion: arbitrary local files are included (and, if they contain PHP, executed) when any visitor requests the page. At time of publication, there are no publicly available patches.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-70650 - GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output decoding of page meta fields and content

CVE ID :CVE-2026-70650
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the page backup viewer (admin/backup-edit.php). Page fields are correctly HTML-encoded when a page is saved, but the backup viewer decodes them again (htmldecode() / strip_decode()) and prints the result without re-escaping. A user who can edit a page can store JavaScript in a page's Keywords, Description, Menu text or Content; it executes in the browser of any administrator who later views that page's backup, in the context of the admin control panel. At time of publication, there are no publicly available patches.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-55252 - OpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect

CVE ID :CVE-2026-55252
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :OpenRun is an open-source, self-hosted GitOps platform for deploying web apps and internal tools to Docker or Kubernetes. Prior to version 0.17.7, the restrictions on redirect URLs in openrun can be bypassed by attackers, leading to open redirect attacks. This issue has been patched in version 0.17.7.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-56662 - GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side update request

CVE ID :CVE-2026-56662
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin verification. A remote attacker can host a page that auto-submits a forged POST to the update endpoint; when an authenticated administrator visits it, the server performs an attacker-directed download-and-deploy operation in the administrator's session — with no further interaction. Because the deployed content is executed (see the related ZIP-extraction advisory), this yields remote code execution. The url field is additionally written into the form unescaped, providing a secondary HTML-injection sink via a malicious upgrade.json. This issue has been patched in version 1.5.
Severity: 9.6 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-56661 - GetSimple CMS: Server-Side Request Forgery in the UpdateCE update endpoint

CVE ID :CVE-2026-56661
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler fetches a user-supplied URL with file_get_contents() after only format validation (FILTER_VALIDATE_URL) — there is no validation of the request destination. An attacker who can submit the form can make the server issue requests to arbitrary destinations, including internal-only services and cloud metadata endpoints (169.254.169.254). The fetched response body is written to a web-accessible file (/Tmpfile.zip) and is not deleted when the content is not a valid ZIP, turning this into a full-read SSRF: the attacker can retrieve the response of the internal request directly. This issue has been patched in version 1.5.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-56660 - GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction

CVE ID :CVE-2026-56660
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without validating file types or extraction paths. Because PHP files are written into a web-accessible directory, an attacker who can cause a malicious archive to be processed achieves remote code execution as the web-server user. Entry names are also used unsafely, allowing directory traversal (../) to write files outside the intended extraction directory. This issue has been patched in version 1.5.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-55251 - NetBox Device Type Library: Arbitrary Code Execution on CI Runner Through Malicious requirements.txt, .pre-commit-hooks-config.yaml, and .gitmodules Files

CVE ID :CVE-2026-55251
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. Prior to commit f41fc1e, the CI workflow .github/workflows/validation.yml runs on pull_request and executes code supplied by the pull request before any maintainer review. Three PR-editable files drive this: "requirements.txt", ".pre-commit-hooks-config.yaml" / ".pre-commit-yamlfmt-config.yaml", and ".gitmodules". A contributor with no special repository access could open a pull request that modifies these files and have their code run on the CI runner. This issue has been patched via commit f41fc1e.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-54049 - Sakai Conversations has a Stored XSS Issue

CVE ID :CVE-2026-54049
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's unsafeHTML() directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversations tool enabled can inject arbitrary HTML and JavaScript that executes in the browsers of all other users who view that topic or post. This issue has been patched in versions 23.5, 25.3, and 26.0.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-53953 - GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover

CVE ID :CVE-2026-53953
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates a new temporary password and immediately stores its hash as the user's new password. The temporary password is generated using PHP rand() seeded with microtime(). Because this seed is time-based and has a limited effective search space, an attacker can generate possible reset password candidates. Since the admin login endpoint does not enforce rate limiting or account lockout, these candidates can be tested online until the correct password is found. Successful exploitation may lead to administrator account takeover. At time of publication, there are no publicly available patches.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-53964 - Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

CVE ID :CVE-2026-53964
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Prior to version 9.1.0, a remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the xltpl library uses a npn-sandboxed Jinja environment for the processing of the template. This issue has been patched in version 9.1.0.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-14984 - Cleartext HTTP for Control Traffic in Teledyne FLIR Robots running Aware2

CVE ID :CVE-2026-14984
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :Cleartext transmission in the primary control endpoints of Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne FLIR PackBot robots running this software via sniffing or hijacking network traffic.
Severity: 9.4 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-14983 - Missing Authentication in Teledyne FLIR Robots running Aware2

CVE ID :CVE-2026-14983
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :Missing authentication in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to achieve denial of service against Teledyne FLIR PackBot robots running this software via misuse of the reboot endpoint.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-104286 - Fortinet FortiMail Path Traversal Vulnerability

CVE ID :CVE-2026-104286
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-103484 - pgvector buffer overflow in IVFFlat index build

CVE ID :CVE-2026-103484
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-102671 - Joyland AI WebView accepts invalid SSL certificates

CVE ID :CVE-2026-102671
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-102670 - Joyland AI enables HTTP

CVE ID :CVE-2026-102670
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :Joyland AI app explicitly permits cleartext HTTP traffic on Android 9+ where the default is to block it.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-102669 - Joyland AI hostname checking disabled

CVE ID :CVE-2026-102669
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :Joyland AI app does not verify hostnames, allowing a malicious host to connect or intercept chat messages.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

CVE-2026-102668 - Joyland AI accepts TLS certificates without validation

CVE ID :CVE-2026-102668
Published : Oct. 1, 2026, 8:17 p.m. | 49 minutes ago
Description :The Joyland AI app accepts any TLS certificates from any server without validation.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 1 Oct 2026 | 8:17 pm UTC

ZDI-CAN-33493: Sangoma

A CVSS score 7.4 AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N severity vulnerability discovered by 'Jonathan Crosby (bitwize)' was reported to the affected vendor on: 2026-10-01, 0 days ago. The vendor is given until 2027-01-29 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 1 Oct 2026 | 5:00 am UTC

ZDI-CAN-33494: Sangoma

A CVSS score 8.8 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Jonathan Crosby (bitwize)' was reported to the affected vendor on: 2026-10-01, 0 days ago. The vendor is given until 2027-01-29 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 1 Oct 2026 | 5:00 am UTC

ZDI-CAN-31742: TrendAI

A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Lays (@_L4ys) of TRAPA Security' was reported to the affected vendor on: 2026-10-01, 0 days ago. The vendor is given until 2027-01-29 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 1 Oct 2026 | 5:00 am UTC

ZDI-CAN-31717: Apple

A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by 'NURIHAN KIM (HanTul)' was reported to the affected vendor on: 2026-10-01, 0 days ago. The vendor is given until 2027-01-29 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 1 Oct 2026 | 5:00 am UTC

ZDI-CAN-33447: Sangoma

A CVSS score 5.9 AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N severity vulnerability discovered by 'Jonathan Crosby (bitwize)' was reported to the affected vendor on: 2026-10-01, 0 days ago. The vendor is given until 2027-01-29 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 1 Oct 2026 | 5:00 am UTC

ZDI-CAN-28318: Valkey

A CVSS score 8.8 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Nenad Stojanovski' was reported to the affected vendor on: 2026-10-01, 0 days ago. The vendor is given until 2027-01-29 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 1 Oct 2026 | 5:00 am UTC

ZDI-CAN-35282: Redis

A CVSS score 8.8 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Nenad Stojanovski' was reported to the affected vendor on: 2026-10-01, 0 days ago. The vendor is given until 2027-01-29 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 1 Oct 2026 | 5:00 am UTC

ZDI-26-751: Microsoft Windows dxgkrnl Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-50375.

Source: ZDI: Published Advisories | 1 Oct 2026 | 5:00 am UTC

ZDI-26-750: WatchGuard FireWare OS spamd statushdlr Stack-based Buffer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-18145.

Source: ZDI: Published Advisories | 30 Sep 2026 | 5:00 am UTC

ZDI-CAN-33817: SoftMaker

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'rgod' was reported to the affected vendor on: 2026-09-30, 1 days ago. The vendor is given until 2027-01-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 30 Sep 2026 | 5:00 am UTC

ZDI-26-749: WatchGuard FireWare OS samld SAMLSession Deserialization of Untrusted Data Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. An attacker must first obtain the ability to write to the samld session directory on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-13046.

Source: ZDI: Published Advisories | 30 Sep 2026 | 5:00 am UTC

ZDI-CAN-32835: Adobe

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-09-28, 3 days ago. The vendor is given until 2027-01-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 28 Sep 2026 | 5:00 am UTC

ZDI-CAN-33157: Adobe

A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-09-28, 3 days ago. The vendor is given until 2027-01-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 28 Sep 2026 | 5:00 am UTC

ZDI-CAN-33156: Adobe

A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-09-28, 3 days ago. The vendor is given until 2027-01-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 28 Sep 2026 | 5:00 am UTC

ZDI-CAN-32875: Adobe

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Juan Pablo Lopez Yacubian' was reported to the affected vendor on: 2026-09-28, 3 days ago. The vendor is given until 2027-01-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 28 Sep 2026 | 5:00 am UTC

ZDI-CAN-33155: Adobe

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-09-28, 3 days ago. The vendor is given until 2027-01-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 28 Sep 2026 | 5:00 am UTC

ZDI-CAN-33440: Adobe

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-09-28, 3 days ago. The vendor is given until 2027-01-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 28 Sep 2026 | 5:00 am UTC

ZDI-CAN-33246: Adobe

A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by 'NURIHAN KIM (HanTul)' was reported to the affected vendor on: 2026-09-28, 3 days ago. The vendor is given until 2027-01-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 28 Sep 2026 | 5:00 am UTC

ZDI-CAN-33033: OpenPrinting

A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Rocco Calvi (@TecR0c) and Edward Morris (edwardgmorris.com) with TecSecurity' was reported to the affected vendor on: 2026-09-25, 6 days ago. The vendor is given until 2027-01-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Sep 2026 | 5:00 am UTC

ZDI-CAN-28504: ATEN

A CVSS score 5.5 AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H severity vulnerability discovered by 'Ahmed Y. Elmogy' was reported to the affected vendor on: 2026-09-25, 6 days ago. The vendor is given until 2027-01-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Sep 2026 | 5:00 am UTC

ZDI-CAN-34489: MailEnable

A CVSS score 8.1 AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Bobby Gould (@bobbygould5) of TrendAI Zero Day Initiative' was reported to the affected vendor on: 2026-09-25, 6 days ago. The vendor is given until 2027-01-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Sep 2026 | 5:00 am UTC

ZDI-CAN-35116: ATEN

A CVSS score 4.9 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N severity vulnerability discovered by 'Ahmed Y. Elmogy' was reported to the affected vendor on: 2026-09-25, 6 days ago. The vendor is given until 2027-01-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 25 Sep 2026 | 5:00 am UTC

ZDI-CAN-31624: LG

A CVSS score 9.8 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Sean de Regge' was reported to the affected vendor on: 2026-09-24, 7 days ago. The vendor is given until 2027-01-22 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 24 Sep 2026 | 5:00 am UTC

ZDI-CAN-33488: Dassault Systèmes

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'ub1cu0' was reported to the affected vendor on: 2026-09-24, 7 days ago. The vendor is given until 2027-01-22 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 24 Sep 2026 | 5:00 am UTC

ZDI-CAN-31722: LG

A CVSS score 9.8 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Sean de Regge' was reported to the affected vendor on: 2026-09-24, 7 days ago. The vendor is given until 2027-01-22 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 24 Sep 2026 | 5:00 am UTC

ZDI-CAN-34296: NVIDIA

A CVSS score 8.8 AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Brandon Evans (@0x1nsomnia), Michael DePlante (@izobashi), and John Simpson (@Thracky) of TrendAI Zero Day Initiative' was reported to the affected vendor on: 2026-09-24, 7 days ago. The vendor is given until 2027-01-22 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 24 Sep 2026 | 5:00 am UTC

ZDI-CAN-33247: Dassault Systèmes

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'ub1cu0' was reported to the affected vendor on: 2026-09-24, 7 days ago. The vendor is given until 2027-01-22 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 24 Sep 2026 | 5:00 am UTC

ZDI-CAN-33111: WatchGuard

A CVSS score 8.8 AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Muhammad Ali' was reported to the affected vendor on: 2026-09-24, 7 days ago. The vendor is given until 2027-01-22 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 24 Sep 2026 | 5:00 am UTC

ZDI-CAN-33245: Dassault Systèmes

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'ub1cu0' was reported to the affected vendor on: 2026-09-24, 7 days ago. The vendor is given until 2027-01-22 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 24 Sep 2026 | 5:00 am UTC

ZDI-26-731: Foxit PDF Reader FileOpen Uninitialized Variable Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91795.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-744: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91816.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-748: Luxion KeyShot BIP File Parsing Uncontrolled Search Path Element Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-92202.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-740: Foxit PDF Reader PRC Stream Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91811.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-734: Foxit PDF Reader RichMedia Annotation Directory Traversal Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91801.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-732: Foxit PDF Reader importIcon NTLM Response Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose NTLM responses on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91796.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-745: Foxit PDF Reader AcroForm Out-of-Bounds Read Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91817.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-746: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91818.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-735: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91806.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-742: Foxit PDF Reader FoxitUpdater Race Condition Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91813.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-736: Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91807.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-737: Foxit PDF Reader JPEG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91808.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-739: Foxit PDF Reader Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91810.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-738: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91809.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-741: Foxit PDF Reader FoxitUpdater Improper Certificate Validation Local Privilege Escalation Vulnerability

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2026-91812.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-733: Foxit PDF Reader Portfolio Directory Traversal Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91797.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-729: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91793.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-724: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91792.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-720: Foxit PDF Reader activeDocs Missing Authorization Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 4.7. The following CVEs are assigned: CVE-2026-91788.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-728: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-57238.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-743: Foxit PDF Reader JPEG2000 Parsing Memory Corruption Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91815.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-725: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-57256.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-726: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-13129.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-747: Wireshark RF4CE Packet Parsing Buffer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Wireshark. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-96417.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-727: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13128.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-722: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91791.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-721: Foxit PDF Reader U3D File Parsing Integer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91789.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-730: Foxit PDF Reader DeviceN Colorspace Out-Of-Bounds Write Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91794.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-723: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91790.

Source: ZDI: Published Advisories | 23 Sep 2026 | 5:00 am UTC

ZDI-26-719: Cisco ThousandEyes Virtual Appliance DHCP Client Command Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco ThousandEyes Virtual Appliance. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20350.

Source: ZDI: Published Advisories | 22 Sep 2026 | 5:00 am UTC

ZDI-CAN-34303: ABRT

A CVSS score 7.0 AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-09-22, 9 days ago. The vendor is given until 2027-01-20 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 22 Sep 2026 | 5:00 am UTC

ZDI-CAN-33068: Deciso

A CVSS score 5.5 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N severity vulnerability discovered by 'Victor Riis Allingham' was reported to the affected vendor on: 2026-09-22, 9 days ago. The vendor is given until 2027-01-20 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 22 Sep 2026 | 5:00 am UTC

ZDI-CAN-32370: Academy Software Foundation

A CVSS score 8.4 AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-09-22, 9 days ago. The vendor is given until 2027-01-20 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 22 Sep 2026 | 5:00 am UTC

ZDI-CAN-33273: Linux

A CVSS score 9.0 AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'msh1307' was reported to the affected vendor on: 2026-09-22, 9 days ago. The vendor is given until 2027-01-20 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 22 Sep 2026 | 5:00 am UTC

ZDI-CAN-34447: ABRT

A CVSS score 5.5 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N severity vulnerability discovered by 'Ryota Shiga(@Ga_ryo_) of GMO Flatt Security' was reported to the affected vendor on: 2026-09-22, 9 days ago. The vendor is given until 2027-01-20 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 22 Sep 2026 | 5:00 am UTC

ZDI-CAN-32377: Academy Software Foundation

A CVSS score 7.4 AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-09-22, 9 days ago. The vendor is given until 2027-01-20 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 22 Sep 2026 | 5:00 am UTC

ZDI-26-718: Cisco Identity Services Engine MnTRESTLivelogService XML External Entity Processing Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2026-20235.

Source: ZDI: Published Advisories | 18 Sep 2026 | 5:00 am UTC

ZDI-26-717: Cisco Identity Services Engine AlarmMessageDiskQueue Deserialization of Untrusted Data Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20211.

Source: ZDI: Published Advisories | 18 Sep 2026 | 5:00 am UTC

ZDI-26-716: Cisco Identity Services Engine createDBLink Command Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20176.

Source: ZDI: Published Advisories | 18 Sep 2026 | 5:00 am UTC

ZDI-26-715: Linux Mint Xreader PDF File Parsing Type Confusion Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19772.

Source: ZDI: Published Advisories | 18 Sep 2026 | 5:00 am UTC

ZDI-CAN-31049: RARLAB

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Landon Peng (Lunbun LLC)' was reported to the affected vendor on: 2026-09-18, 13 days ago. The vendor is given until 2027-01-16 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 18 Sep 2026 | 5:00 am UTC

ZDI-CAN-33838: Medixant

A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by 'ub1cu0' was reported to the affected vendor on: 2026-09-18, 13 days ago. The vendor is given until 2027-01-16 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 18 Sep 2026 | 5:00 am UTC

ZDI-CAN-33843: Medixant

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'ub1cu0' was reported to the affected vendor on: 2026-09-18, 13 days ago. The vendor is given until 2027-01-16 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 18 Sep 2026 | 5:00 am UTC

ZDI-CAN-33841: Medixant

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'ub1cu0' was reported to the affected vendor on: 2026-09-18, 13 days ago. The vendor is given until 2027-01-16 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 18 Sep 2026 | 5:00 am UTC

ZDI-CAN-32596: Parallels

A CVSS score 8.2 AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Ankur Saini of Volexity' was reported to the affected vendor on: 2026-09-18, 13 days ago. The vendor is given until 2027-01-16 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 18 Sep 2026 | 5:00 am UTC

ZDI-CAN-33842: Medixant

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'ub1cu0' was reported to the affected vendor on: 2026-09-18, 13 days ago. The vendor is given until 2027-01-16 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 18 Sep 2026 | 5:00 am UTC

count: 100