Radar
A personal hobby project. Radar aggregates security advisories from CISA, Zero Day Initiative and CERT-EU and adds short editorial highlights on what I find notable from a European infrastructure perspective — not a threat-intel service, not exhaustive, just what catches my eye.
-
ZDI-26-101: Oracle VirtualBox BusLogic Uninitialized Memory Information Disclosure Vulnerability
The vulnerability requires local execution of high-privileged code on a guest system. The CVSS rating is 6.0.
Read more → -
ZDI-26-102: Oracle VirtualBox VMSVGA Out-Of-Bounds Write Local Privilege Escalation Vulnerability
The vulnerability requires an attacker to already have high-privileged code execution on the guest system. The exploit targets the VirtualBox VMSVGA virtual device.
Read more → -
ZDI-26-103: Oracle VirtualBox VMSVGA Out-Of-Bounds Access Local Privilege Escalation Vulnerability
This vulnerability requires an attacker to already have high-privileged code execution on the guest system. The exploit targets the VMSVGA virtual graphics component within Oracle VirtualBox.
Read more → -
ZDI-26-104: Sante DICOM Viewer Pro DCM File Parsing Buffer Overflow Remote Code Execution Vulnerability
The vulnerability is triggered by parsing a malicious DCM file, requiring user interaction to open the file or visit a malicious page.
Read more → -
ZDI-26-105: MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability
The vulnerability affects the MLflow Tracking Server's Artifact Handler, allowing remote code execution via directory traversal without authentication.
Read more → -
2026-001: Critical vulnerabilities in Ivanti EPMM
One of the vulnerabilities has been exploited in a limited number of cases. The advisory addresses two critical vulnerabilities enabling unauthenticated remote code execution.
Read more → -
2025-042: Critical Vulnerability in Cisco Secure Email and Web Manager
No patch is currently available for this vulnerability. Cisco recommends checking for signs of compromise on affected appliances.
Read more → -
2025-041: Critical Security Vulnerability in React Server Components
React Server Components vulnerability enables unauthenticated remote code execution via HTTP requests. The React Team disclosed this on December 3, 2025.
Read more → -
2025-040: Critical Vulnerability in Windows Server Update Service (WSUS)
A proof-of-concept exploit is publicly available for this WSUS vulnerability. The update was released out-of-band by Microsoft.
Read more → -
2025-039: High Severity Vulnerability in FortiOS
Fortinet released an advisory for a high-severity FortiOS vulnerability on October 14, 2025. The advisory recommends updating affected products.
Read more → -
2025-038: Critical Vulnerabilities in Veeam Backup
Veeam Backup has two critical vulnerabilities requiring immediate update. The advisory does not detail specific exploitation conditions or affected deployment contexts.
Read more → -
2025-037: Multiple Vulnerabilities in F5 Products
A nation-state actor accessed F5's source code and undisclosed vulnerability information. Patches were released on the same day as the disclosure.
Read more →
Page 11 of 11 · 1,012 advisories