jell.ie CVEs

Read at: 2026-09-10T10:59:37+00:00

CVE-2026-78302 - Joomla Extension - joomshaper.com - Unauthenticated Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4

CVE ID :CVE-2026-78302
Published : Sept. 10, 2026, 10:02 a.m. | 21 minutes ago
Description :Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 - Multiple template files across frontend views and administrator list tables rendered attributes and text values directly into HTML without contextual escaping.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 10:02 am UTC

CVE-2026-78374 - Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0

CVE ID :CVE-2026-78374
Published : Sept. 10, 2026, 10:01 a.m. | 21 minutes ago
Description :Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 - The front-end JSON editor endpoint exposes an action called contact that requires no authentication, no CSRF token, no captcha (when no captcha plugin is enabled) and has no rate limiting. The attacker fully controls the recipient, subject and HTML body, and the mail is sent from the site's configured sender identity (mailfrom/fromname).
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 10:01 am UTC

CVE-2026-78083 - Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4

CVE ID :CVE-2026-78083
Published : Sept. 10, 2026, 10:01 a.m. | 22 minutes ago
Description :Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 - The visitor booking (properties.booking) and agent contact form submission (agents.sendmail) endpoints processed POST requests without verifying Joomla session anti-CSRF tokens.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 10:01 am UTC

CVE-2026-78084 - Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4

CVE ID :CVE-2026-78084
Published : Sept. 10, 2026, 10 a.m. | 22 minutes ago
Description :Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked authorization checks and CSRF token validation.. Users could invoke file removal actions with arbitrary path strings or upload unverified file types.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 10:00 am UTC

CVE-2026-78082 - Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4

CVE ID :CVE-2026-78082
Published : Sept. 10, 2026, 9:59 a.m. | 23 minutes ago
Description :Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting, price_range_dropdown, and psize_range_dropdown) by directly concatenating raw request parameters into SQL strings without quoting or type casting. An unauthenticated remote attacker could execute boolean-based or time-based blind SQL injection to extract sensitive data from the database.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:59 am UTC

CVE-2026-78303 - Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4

CVE ID :CVE-2026-78303
Published : Sept. 10, 2026, 9:56 a.m. | 27 minutes ago
Description :Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing potential email manipulation.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:56 am UTC

CVE-2026-87803 - Countly Server DBViewer Authorization Bypass

CVE ID :CVE-2026-87803
Published : Sept. 10, 2026, 9:54 a.m. | 29 minutes ago
Description :An authorization bypass vulnerability exists in the Countly Server DBViewer due to flawed sub-pipeline detection in the aggregation stage sanitizer. The /o/db aggregation endpoint parses user-controlled aggregation JSON and passes it through a stage sanitizer that determines whether a nested array is a sub-pipeline by checking if every element contains a key present in a hardcoded KNOWN_STAGE_OPERATORS set. If any element contains an unrecognized stage key, such as the undocumented MongoDB-internal $_internalInhibitOptimization, the sanitizer misclassifies the entire branch as a generic array and skips stage-level stripping for all sibling stages. This allows a non-admin user with DBViewer read permission to inject forbidden operators like $lookup inside $facet sub-pipelines, performing cross-collection joins into restricted collections. This leads to unauthorized read access to sensitive data including password-reset tokens (prid), enabling account takeover.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:54 am UTC

CVE-2026-15889 - Aruba HiSpeed Cache <= 3.0.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Content

CVE ID :CVE-2026-15889
Published : Sept. 10, 2026, 9:27 a.m. | 56 minutes ago
Description :The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Content in all versions up to, and including, 3.0.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:27 am UTC

CVE-2026-5399 - Redux Framework <= 4.5.13.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Slider Field Value

CVE ID :CVE-2026-5399
Published : Sept. 10, 2026, 9:27 a.m. | 56 minutes ago
Description :The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider field in User Profile settings in versions up to and including 4.5.13.1. This is due to insufficient input sanitization in the user_meta_save() function (which only sanitizes array values, not scalar values) and improper output escaping in the Redux_Slider::render() method, which outputs slider values into unquoted HTML attributes. The vulnerability also exploits the fact that the clean_default() method only casts values to numeric types when they are empty or out of bounds, allowing malicious strings like '1 tabindex=0 autofocus onfocus=alert(1) x=' to pass validation through PHP's loose type comparison. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts into their user profile that will execute whenever an Administrator navigates to view the attacker's profile page.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:27 am UTC

CVE-2026-88290 - GV-LPC2011/LPC2211 - Unauthenticated VLSVR Slowloris and Memory Resource Exhaustion

CVE ID :CVE-2026-88290
Published : Sept. 10, 2026, 9:17 a.m. | 1 hour, 6 minutes ago
Description :GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:17 am UTC

CVE-2026-88289 - GV-LPC2011/LPC2211 - Multiple Pre-Authentication Stack Buffer Overflows in VLSVR Request Handlers

CVE ID :CVE-2026-88289
Published : Sept. 10, 2026, 9:17 a.m. | 1 hour, 6 minutes ago
Description :GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:17 am UTC

CVE-2026-8323 - Open Redirect in Armiya Information Technologies' Access Control System

CVE ID :CVE-2026-8323
Published : Sept. 10, 2026, 9:17 a.m. | 1 hour, 6 minutes ago
Description :URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data. This issue affects Access Control System: before Versiyon 2.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:17 am UTC

CVE-2026-88286 - GV-LPC2011/LPC2211 - PTZ Connection-State Accept-Loop Denial of Service

CVE ID :CVE-2026-88286
Published : Sept. 10, 2026, 9:17 a.m. | 1 hour, 6 minutes ago
Description :GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection state, allowing an unauthenticated remote client to block the accept loop and prevent new PTZ connections.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:17 am UTC

CVE-2026-88281 - GV-LPC2011/LPC2211 - ONVIF DeleteUsers Repeated-Element Stack Overflow Denial of Service

CVE ID :CVE-2026-88281
Published : Sept. 10, 2026, 9:17 a.m. | 1 hour, 6 minutes ago
Description :GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated administrator to overflow a stack array and crash the ONVIF worker.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:17 am UTC

CVE-2026-88282 - GV-LPCLPC2011/2211 - Stored FTP-Username Command Injection

CVE ID :CVE-2026-88282
Published : Sept. 10, 2026, 9:17 a.m. | 1 hour, 6 minutes ago
Description :GeoVision GV-LPC2211 V1.13 allows an administrator-controlled FTP username containing shell metacharacters to be executed as arbitrary root commands during a subsequent FTP-account update.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:17 am UTC

CVE-2026-88283 - GV-LPC2011/LPC2211 - ONVIF CreateUsers Repeated-Element Stack-Frame Overflow Denial of Service

CVE ID :CVE-2026-88283
Published : Sept. 10, 2026, 9:17 a.m. | 1 hour, 6 minutes ago
Description :GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:17 am UTC

CVE-2026-88285 - GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service

CVE ID :CVE-2026-88285
Published : Sept. 10, 2026, 9:17 a.m. | 1 hour, 6 minutes ago
Description :GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands.
Severity: 9.4 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:17 am UTC

CVE-2026-88284 - GV-LPC2011/LPC2211 - ONVIF SetUser Repeated-Element Stack-Frame Overflow Denial of Service

CVE ID :CVE-2026-88284
Published : Sept. 10, 2026, 9:17 a.m. | 1 hour, 6 minutes ago
Description :GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF SetUser requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:17 am UTC

CVE-2026-88287 - GV-LPC2011/LPC2211 -ONVIF Discovery Probe Scopes Stack-Frame Overflow Denial of Service

CVE ID :CVE-2026-88287
Published : Sept. 10, 2026, 9:17 a.m. | 1 hour, 6 minutes ago
Description :GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:17 am UTC

CVE-2026-88280 - GV-LPC2011/LPC2211 - ONVIF SetUser Stack-Frame Overflow Denial of Service

CVE ID :CVE-2026-88280
Published : Sept. 10, 2026, 9:17 a.m. | 1 hour, 6 minutes ago
Description :GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticated administrator to crash the ONVIF worker.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:17 am UTC

CVE-2026-88288 - GV-LPC2011/LPC2211 - Arbitrary File Read Through BKDownloadLink.cgi Symlink Creation

CVE ID :CVE-2026-88288
Published : Sept. 10, 2026, 9:17 a.m. | 1 hour, 6 minutes ago
Description :GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:17 am UTC

CVE-2026-88278 - GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest Replay

CVE ID :CVE-2026-88278
Published : Sept. 10, 2026, 9:17 a.m. | 1 hour, 6 minutes ago
Description :GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:17 am UTC

CVE-2026-88277 - GV-LPCLPC2011/2211 - ONVIF Subscribe Address Command Injection

CVE ID :CVE-2026-88277
Published : Sept. 10, 2026, 9:17 a.m. | 1 hour, 6 minutes ago
Description :GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands through ConsumerReference.Address and execute arbitrary commands as root.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:17 am UTC

CVE-2026-88279 - GV-LPC2011/LPC2211 - ONVIF CreateUsers Username/Password Stack-Frame Overflow Denial of Service

CVE ID :CVE-2026-88279
Published : Sept. 10, 2026, 9:17 a.m. | 1 hour, 6 minutes ago
Description :GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:17 am UTC

CVE-2026-88276 - GV-LPCLPC2011/2211 - Wireless WEP Key1-Key4 Command Injection

CVE ID :CVE-2026-88276
Published : Sept. 10, 2026, 9:17 a.m. | 1 hour, 6 minutes ago
Description :GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to execute arbitrary commands as root.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Source: Latest Vulnerabilities | 10 Sep 2026 | 9:17 am UTC

ZDI-CAN-33987: Foxit

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-09-09, 1 days ago. The vendor is given until 2027-01-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-CAN-32723: Langflow

A CVSS score 5.0 AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N severity vulnerability discovered by 'p0her (@_p0her_) of TeamH4C' was reported to the affected vendor on: 2026-09-09, 1 days ago. The vendor is given until 2027-01-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-CAN-33055: PyTorch Foundation

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Alex Williams (https://www.al443x.com)' was reported to the affected vendor on: 2026-09-09, 1 days ago. The vendor is given until 2027-01-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-CAN-32818: VMware

A CVSS score 7.8 AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Dang Minh Quang of Viettel Cyber Security' was reported to the affected vendor on: 2026-09-09, 1 days ago. The vendor is given until 2027-01-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-CAN-33990: Foxit

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-09-09, 1 days ago. The vendor is given until 2027-01-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-CAN-33415: Autodesk

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Berat.İ' was reported to the affected vendor on: 2026-09-09, 1 days ago. The vendor is given until 2027-01-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-CAN-33584: Cisco

A CVSS score 5.3 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N severity vulnerability discovered by 'Connor Kastner (ret2c)' was reported to the affected vendor on: 2026-09-09, 1 days ago. The vendor is given until 2027-01-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-CAN-32892: Autodesk

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Berat.İ' was reported to the affected vendor on: 2026-09-09, 1 days ago. The vendor is given until 2027-01-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-CAN-32294: Next.js

A CVSS score 5.9 AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N severity vulnerability discovered by 'Anas Almizani (@x6vrn)' was reported to the affected vendor on: 2026-09-09, 1 days ago. The vendor is given until 2027-01-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-644: Oracle VirtualBox VMSVGA Race Condition Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-60155.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-643: Oracle VirtualBox VMSVGA Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-60162.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-646: Progress Software Kemp LoadMaster escape_quotes Uninitialized Memory Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-8037.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-CAN-33570: Foxit

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by '06fe5fd2bc53027c4a3b7e395af0b850e7b8a044' was reported to the affected vendor on: 2026-09-09, 1 days ago. The vendor is given until 2027-01-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-623: Linux Kernel IPv6 Multicast Routing Use-After-Free Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-633: GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-4153.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-639: Oracle VirtualBox VMSVGA Heap-based Buffer Overflow Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-71116.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-627: Backblaze Personal Computer Backup bztransmit Link Following Denial-of-Service Vulnerability

This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-636: Oracle Outside In Technology PostScript File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60412.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-628: Backblaze Personal Computer Backup bzreports Link Following Denial-of-Service Vulnerability

This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-635: Oracle Outside In Technology PDF File Parsing Integer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must open a malicious file or visit a malicious page. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60392.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-626: Backblaze Personal Computer Backup bzfilelist Link Following Denial-of-Service Vulnerability

This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-624: Backblaze Personal Computer Backup bzbackup Link Following Denial-of-Service Vulnerability

This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-632: WatchGuard FireWare OS epm connect Stack-based Buffer Overflow Remote Code Execution Vulnerability

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-13086.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-647: VMware Workstation VMXNET3 TSO Segmentation Integer Overflow Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of VMware Workstation. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-59346.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-641: Oracle VirtualBox VirtioSCSI Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-71114.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-637: Oracle Outside In Technology GEM File Parsing Integer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60413.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-642: Oracle VirtualBox IDisplay Out-Of-Bounds Read Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-60159.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-630: NI LabVIEW VI File Parsing Integer Overflow Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-18445.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-640: Oracle VirtualBox VirtioSCSI Uninitialized Memory Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2026-71132.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-638: Oracle Outside In Technology WPS File Parsing Memory Corruption Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60414.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-629: Microsoft Azure Entra ID OAuth Device Code Grant Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Azure. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.8.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-631: NI LabVIEW VI File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-18444.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-625: Backblaze Personal Computer Backup bzserv Link Following Denial-of-Service Vulnerability

This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-645: Fortinet FortiSandbox write_remote_backup_to_crontab cronValue Command Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fortinet FortiSandbox. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-84387.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-634: Flowise CSV Agent Prompt Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-70477.

Source: ZDI: Published Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-CAN-33989: Foxit

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-09-09, 1 days ago. The vendor is given until 2027-01-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 9 Sep 2026 | 5:00 am UTC

ZDI-26-622: Microsoft Windows IKEv2 AES-GCM Decryption Integer Underflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Authentication is not required to exploit this vulnerability, but only systems with specific IPsec configurations are vulnerable. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-50696.

Source: ZDI: Published Advisories | 8 Sep 2026 | 5:00 am UTC

ZDI-26-618: Microsoft Windows UMPDDrvStretchBlt Improper Object Management Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

Source: ZDI: Published Advisories | 8 Sep 2026 | 5:00 am UTC

ZDI-26-617: Microsoft Windows MIDI Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66804.

Source: ZDI: Published Advisories | 8 Sep 2026 | 5:00 am UTC

ZDI-26-621: Microsoft Windows UMPDDrvRealizeBrush Improper Object Management Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

Source: ZDI: Published Advisories | 8 Sep 2026 | 5:00 am UTC

ZDI-26-620: Microsoft Windows UMPDDrvPlgBlt Improper Object Management Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

Source: ZDI: Published Advisories | 8 Sep 2026 | 5:00 am UTC

ZDI-26-616: Koha Eval Code Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-19780.

Source: ZDI: Published Advisories | 8 Sep 2026 | 5:00 am UTC

ZDI-26-619: Microsoft Windows UMPDDrvStretchBltROP Improper Object Management Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

Source: ZDI: Published Advisories | 8 Sep 2026 | 5:00 am UTC

ZDI-CAN-30923: Microsoft

A CVSS score 3.1 AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by 'Kyeongmin Kim (@hareh4ru) of KAIST Hacking Lab' was reported to the affected vendor on: 2026-09-04, 6 days ago. The vendor is given until 2027-01-02 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 4 Sep 2026 | 5:00 am UTC

ZDI-CAN-31571: Microsoft

A CVSS score 4.3 AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N severity vulnerability discovered by 'Hlib Yavorskyi' was reported to the affected vendor on: 2026-09-04, 6 days ago. The vendor is given until 2027-01-02 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 4 Sep 2026 | 5:00 am UTC

ZDI-CAN-30756: Microsoft

A CVSS score 7.5 AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Kyeongmin Kim (@hareh4ru) of KAIST Hacking Lab' was reported to the affected vendor on: 2026-09-04, 6 days ago. The vendor is given until 2027-01-02 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 4 Sep 2026 | 5:00 am UTC

ZDI-CAN-32917: Autodesk

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'ub1cu0' was reported to the affected vendor on: 2026-09-03, 7 days ago. The vendor is given until 2027-01-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Sep 2026 | 5:00 am UTC

ZDI-CAN-32580: Microsoft

A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by 'Len Sadowski (lytnc) and Oğuz Bektaş (_ozb_)' was reported to the affected vendor on: 2026-09-03, 7 days ago. The vendor is given until 2027-01-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Sep 2026 | 5:00 am UTC

ZDI-CAN-30555: Microsoft

A CVSS score 7.5 AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Kyeongmin Kim (@hareh4ru) of KAIST Hacking Lab' was reported to the affected vendor on: 2026-09-03, 7 days ago. The vendor is given until 2027-01-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Sep 2026 | 5:00 am UTC

ZDI-CAN-32263: Microsoft

A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by 'Len Sadowski (lytnc) and Oğuz Bektaş (_ozb_)' was reported to the affected vendor on: 2026-09-03, 7 days ago. The vendor is given until 2027-01-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Sep 2026 | 5:00 am UTC

ZDI-CAN-32257: Microsoft

A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by 'Len Sadowski (lytnc) and Oğuz Bektaş (_ozb_)' was reported to the affected vendor on: 2026-09-03, 7 days ago. The vendor is given until 2027-01-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Sep 2026 | 5:00 am UTC

ZDI-CAN-32899: Autodesk

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'ub1cu0' was reported to the affected vendor on: 2026-09-03, 7 days ago. The vendor is given until 2027-01-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Sep 2026 | 5:00 am UTC

ZDI-CAN-33777: Trimble

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'kai63001' was reported to the affected vendor on: 2026-09-03, 7 days ago. The vendor is given until 2027-01-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Sep 2026 | 5:00 am UTC

ZDI-CAN-34163: VMware

A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Nicholas Zubrisky (@NZubrisky) of TrendAI Zero Day Initiative' was reported to the affected vendor on: 2026-09-03, 7 days ago. The vendor is given until 2027-01-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Sep 2026 | 5:00 am UTC

ZDI-CAN-32649: LiteLLM

A CVSS score 6.5 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N severity vulnerability discovered by 's3zer0' was reported to the affected vendor on: 2026-09-03, 7 days ago. The vendor is given until 2027-01-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Sep 2026 | 5:00 am UTC

ZDI-CAN-32574: Microsoft

A CVSS score 3.1 AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by 'Len Sadowski (lytnc) and Oğuz Bektaş (_ozb_)' was reported to the affected vendor on: 2026-09-03, 7 days ago. The vendor is given until 2027-01-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Sep 2026 | 5:00 am UTC

ZDI-CAN-32421: RAGFlow

A CVSS score 8.8 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 's3zer0' was reported to the affected vendor on: 2026-09-03, 7 days ago. The vendor is given until 2027-01-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Sep 2026 | 5:00 am UTC

ZDI-CAN-32869: Linux

A CVSS score 7.8 AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'caveeroo' was reported to the affected vendor on: 2026-09-03, 7 days ago. The vendor is given until 2027-01-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Sep 2026 | 5:00 am UTC

ZDI-CAN-30922: VMware

A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'SAI WIN MYAT (Valen)' was reported to the affected vendor on: 2026-09-03, 7 days ago. The vendor is given until 2027-01-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Sep 2026 | 5:00 am UTC

ZDI-CAN-28931: AOMEI

A CVSS score 4.9 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-09-03, 7 days ago. The vendor is given until 2027-01-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Sep 2026 | 5:00 am UTC

ZDI-CAN-32898: Autodesk

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'ub1cu0' was reported to the affected vendor on: 2026-09-03, 7 days ago. The vendor is given until 2027-01-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Sep 2026 | 5:00 am UTC

ZDI-CAN-32856: NVIDIA

A CVSS score 7.2 AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N severity vulnerability discovered by 'Habibullo Izzatilloyev' was reported to the affected vendor on: 2026-09-03, 7 days ago. The vendor is given until 2027-01-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Sep 2026 | 5:00 am UTC

ZDI-CAN-30361: Docker

A CVSS score 7.5 AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Florian K' was reported to the affected vendor on: 2026-09-03, 7 days ago. The vendor is given until 2027-01-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Sep 2026 | 5:00 am UTC

ZDI-CAN-32860: NVIDIA

A CVSS score 9.8 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Habibullo Izzatilloyev' was reported to the affected vendor on: 2026-09-03, 7 days ago. The vendor is given until 2027-01-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Sep 2026 | 5:00 am UTC

ZDI-CAN-32773: Dassault Systèmes

A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'kai63001' was reported to the affected vendor on: 2026-09-03, 7 days ago. The vendor is given until 2027-01-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 3 Sep 2026 | 5:00 am UTC

ZDI-CAN-32093: X.Org

A CVSS score 8.8 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Adam Bedard' was reported to the affected vendor on: 2026-09-02, 8 days ago. The vendor is given until 2026-12-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 2 Sep 2026 | 5:00 am UTC

ZDI-CAN-32408: X.Org

A CVSS score 6.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L severity vulnerability discovered by 'WONJOON HWANG (@joon1337)' was reported to the affected vendor on: 2026-09-02, 8 days ago. The vendor is given until 2026-12-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 2 Sep 2026 | 5:00 am UTC

ZDI-CAN-33360: Linux

A CVSS score 7.5 AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'GangMin Kim' was reported to the affected vendor on: 2026-09-02, 8 days ago. The vendor is given until 2026-12-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 2 Sep 2026 | 5:00 am UTC

ZDI-CAN-32542: NVIDIA

A CVSS score 10.0 AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Habibullo Izzatilloyev' was reported to the affected vendor on: 2026-09-02, 8 days ago. The vendor is given until 2026-12-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 2 Sep 2026 | 5:00 am UTC

ZDI-CAN-34034: VMware

A CVSS score 9.8 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'NiNi (@terrynini38514) from the DEVCORE Research Team' was reported to the affected vendor on: 2026-09-02, 8 days ago. The vendor is given until 2026-12-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 2 Sep 2026 | 5:00 am UTC

ZDI-CAN-32061: X.Org

A CVSS score 8.8 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Adam Bedard' was reported to the affected vendor on: 2026-09-02, 8 days ago. The vendor is given until 2026-12-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 2 Sep 2026 | 5:00 am UTC

ZDI-CAN-33385: Devin

A CVSS score 7.3 AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Xavier DANEST' was reported to the affected vendor on: 2026-09-02, 8 days ago. The vendor is given until 2026-12-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 2 Sep 2026 | 5:00 am UTC

ZDI-CAN-32224: NVIDIA

A CVSS score 9.8 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'YJK(@YJK0805) of ZUSO ART' was reported to the affected vendor on: 2026-09-02, 8 days ago. The vendor is given until 2026-12-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 2 Sep 2026 | 5:00 am UTC

ZDI-CAN-32436: Linux

A CVSS score 6.3 AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2026-09-02, 8 days ago. The vendor is given until 2026-12-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 2 Sep 2026 | 5:00 am UTC

ZDI-CAN-31888: X.Org

A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Adam Bedard' was reported to the affected vendor on: 2026-09-02, 8 days ago. The vendor is given until 2026-12-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Source: ZDI: Upcoming Advisories | 2 Sep 2026 | 5:00 am UTC

count: 100