Radar
A personal hobby project. Radar aggregates security advisories from CISA, Zero Day Initiative and CERT-EU and adds short editorial highlights on what I find notable from a European infrastructure perspective — not a threat-intel service, not exhaustive, just what catches my eye.
-
ZDI-26-455: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
GIMP’s TIF parser contains a heap-based buffer overflow that can be triggered by a crafted TIF file.
Read more → -
ZDI-26-456: GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
The flaw is a stack-based buffer overflow in GIMP’s TIF parser that requires the victim to open a crafted file or page.
Read more → -
ZDI-26-457: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability
GIMP’s TIF parser contains an integer overflow that can be triggered by a crafted TIF file.
Read more → -
ZDI-26-458: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability
The flaw is an integer overflow in GIMP’s TIF parser that can be triggered by a crafted file. Exploitation requires the victim to open the file or view it via a malicious page.
Read more → -
ZDI-26-459: GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability
The flaw is an integer overflow in GIMP's SGI file parser that requires the victim to open a crafted file or page.
Read more → -
ZDI-26-460: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Exploitation requires a user to open a crafted TIF file or view it via a malicious web page. The vulnerability is a heap-based buffer overflow in GIMP’s TIF parser.
Read more → -
ZDI-26-461: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability
GIMP’s TIF file parser contains an integer overflow that can be triggered by a crafted TIF file, leading to remote code execution. Exploitation requires the victim to open the malicious file or load a page hosting it.
Read more → -
ZDI-26-462: GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerability
Exploitation requires a user to open a crafted APNG file or visit a page delivering it.
Read more → -
ZDI-26-463: GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Exploitation requires the victim to open a malicious file or visit a malicious page.
Read more → -
ZDI-26-464: GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Exploitation requires a victim to open a malicious file or visit a malicious page.
Read more → -
ZDI-26-465: GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Exploitation requires a user to open a malicious OGG file or visit a crafted page.
Read more → -
ZDI-26-466: GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
GStreamer’s PNG parser suffers a heap-based buffer overflow.
Read more → -
ZDI-26-467: GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability
The advisory notes a use-after-free in GStreamer’s rtpsbcdepay element that can be remotely triggered.
Read more → -
ZDI-26-468: Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerability
Remote code execution is possible via deserialization of untrusted data in Aeon's load_rehab_pile_dataset function, requiring the victim to load a malicious page or file.
Read more → -
ZDI-26-469: Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerability
Remote code execution is possible if a user visits a malicious page or opens a malicious file while using aeon.
Read more → -
ZDI-26-470: Aeon load_time_series_segmentation_benchmark Code Injection Remote Code Execution Vulnerability
Exploitation requires the victim to load a malicious page or file. The flaw permits remote code execution with a CVSS score of 7.8.
Read more → -
ZDI-26-471: (Pwn2Own) Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability
The exploit requires a malicious Bluetooth device to be paired before information disclosure can occur.
Read more → -
ZDI-26-472: (Pwn2Own) Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability
Unauthenticated attackers on the same network can trigger a buffer overflow via the RTSP SETUP command.
Read more → -
ZDI-26-473: (Pwn2Own) Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability
Physically present attackers can exploit the vulnerability without authentication. The advisory assigns a CVSS score of 3.9.
Read more → -
ZDI-26-474: (Pwn2Own) Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability
Exploitation requires a successful Bluetooth pairing before the heap overflow can be triggered.
Read more → -
ZDI-26-475: (Pwn2Own) Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability
The heap-based buffer overflow resides in the AVRCP_Br_Response_Parser of the Sony XAV-9500ES. Exploitation requires a Bluetooth device to be paired with the unit.
Read more → -
ZDI-26-476: (Pwn2Own) Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability
Physical attackers can bypass authorization on Sony XAV-9500ES devices via the udev USB rules.
Read more → -
ZDI-26-477: (Pwn2Own) Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerability
The advisory reports a local privilege escalation via command injection in the crash dump handler of Sony XAV-9500ES.
Read more → -
ZDI-26-478: Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability
Adminer installations are vulnerable to remote code execution due to an incorrect check of the multi_query function’s return value.
Read more → -
ZDI-26-479: Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability
Authentication is required to exploit the uploadJar directory traversal RCE in Heimdall Data Database Proxy.
Read more → -
ZDI-26-480: OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability
OSNEXUS QuantaStor can be remotely compromised without authentication.
Read more → -
ZDI-26-481: Progress Software Kemp LoadMaster access Missing Authorization Privilege Escalation Vulnerability
Remote attackers can gain higher privileges on Progress Software Kemp LoadMaster after authenticating.
Read more → -
ZDI-26-482: Progress Software Kemp LoadMaster enablexroot Use of Hard-Coded Cryptographic Key Privilege Escalation Vulnerability
Remote authenticated attackers can gain higher privileges on Kemp LoadMaster due to a hard-coded cryptographic key.
Read more → -
ZDI-26-483: NoMachine getstat Command Injection Remote Code Execution Vulnerability
Exploitation of the NoMachine getstat command requires authentication.
Read more → -
ZDI-26-484: (Pwn2Own) Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability
Unauthenticated code execution is possible via the firmware update link on Kenwood DNR1007XR devices.
Read more → -
ZDI-26-485: (Pwn2Own) Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability
The advisory reports a command injection in JKGenService that enables local privilege escalation on Kenwood DNR1007XR devices.
Read more → -
ZDI-26-486: (Pwn2Own) Kenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write Code Execution Vulnerability
Unauthenticated physically present attackers can achieve arbitrary code execution on Kenwood DNR1007XR devices.
Read more → -
ZDI-26-447: Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability
Remote code execution is possible via a CRLF injection in generateFileContent, but authentication is required. The advisory assigns a CVSS score of 7.2.
Read more → -
ZDI-26-448: Bitdefender Total Security Shredder Link Following Local Privilege Escalation Vulnerability
The vulnerability enables privilege escalation from a low-privileged process on Bitdefender Total Security.
Read more → -
ZDI-26-449: AzeoTech DAQFactory CTL File Parsing Type Confusion Remote Code Execution Vulnerability
Exploitation requires a victim to load a malicious CTL file via a web page or local file.
Read more → -
ZDI-26-450: AzeoTech DAQFactory CTL File Parsing Use-After-Free Remote Code Execution Vulnerability
Exploitation requires a victim to open a crafted CTL file or visit a malicious page, triggering a use-after-free.
Read more → -
ZDI-26-451: Docker Desktop for macOS Inference Server Permissive Allow List Sandbox Escape Vulnerability
Docker Desktop for macOS's model runner sandbox can be escaped by a local attacker who already has low-privileged code execution inside the sandbox.
Read more → -
ZDI-26-452: Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability
The vulnerability is an open redirect in Dify’s oauth_redirect_url parameter.
Read more → -
ZDI-26-445: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability
The advisory notes a local privilege escalation via incorrect authorization in Windows WMI providers.
Read more → -
ZDI-26-446: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability
The advisory notes a local privilege escalation via incorrect authorization in Windows WMI providers.
Read more → -
ZDI-26-444: 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
Heap-based buffer overflow in 7-Zip’s XZ decompression can lead to remote code execution when a crafted file is opened.
Read more → -
ZDI-26-405: X.Org Server GLX Extension Use-After-Free Privilege Escalation Vulnerability
The GLX extension in X.Org Server contains a use-after-free that enables local privilege escalation.
Read more → -
ZDI-26-406: X.Org Server BitmapScaleBitmaps Integer Overflow Privilege Escalation Vulnerability
An integer overflow in the BitmapScaleBitmaps function of X.Org Server can be leveraged for local privilege escalation.
Read more → -
ZDI-26-407: X.Org Server PCF Font Parsing Heap-based Buffer Overflow Privilege Escalation Vulnerability
Heap-based buffer overflow in X.Org Server's PCF font parser enables local privilege escalation.
Read more → -
ZDI-26-408: X.Org Server ComputeScaledProperties Heap-based Buffer Overflow Privilege Escalation Vulnerability
The advisory notes a heap-based buffer overflow in ComputeScaledProperties of X.Org Server that enables local privilege escalation.
Read more → -
ZDI-26-409: X.Org Server Glamor Font Heap-based Buffer Overflow Privilege Escalation Vulnerability
A heap-based buffer overflow in Glamor font handling of X.Org Server enables local privilege escalation.
Read more → -
ZDI-26-410: NVIDIA NeMo Framework Deserialization of Untrusted Data Remote Code Execution Vulnerability
Exploitation requires the victim to visit a malicious page or open a malicious file.
Read more → -
ZDI-26-411: NVIDIA NVTabular Pickle File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability
NVTabular deserializes untrusted pickle files, enabling remote code execution when a user opens a malicious file or visits a crafted page.
Read more → -
ZDI-26-412: (Pwn2Own) Microsoft SharePoint Deserialization of Untrusted Data Remote Code Execution Vulnerability
Unauthenticated remote code execution via SharePoint deserialization.
Read more → -
ZDI-26-413: (Pwn2Own) Microsoft SharePoint Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability
Unauthenticated remote code execution is possible on Microsoft SharePoint via improper verification of cryptographic signatures.
Read more → -
ZDI-26-414: Microsoft PowerShell Help Directory Traversal Remote Code Execution Vulnerability
PowerShell’s help system can be traversed to achieve remote code execution when a user opens a malicious file or visits a malicious page.
Read more → -
ZDI-26-415: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability
The advisory notes an incorrect authorization issue in Windows WMI providers that enables local privilege escalation.
Read more → -
ZDI-26-416: Microsoft Hyper-V netvsc Out-Of-Bounds Read Local Privilege Escalation Vulnerability
The netvsc driver contains an out-of-bounds read that can be leveraged for local privilege escalation.
Read more → -
ZDI-26-417: Microsoft Windows ServerManager Exposed Dangerous Method Local Privilege Escalation Vulnerability
The advisory describes a local privilege escalation vulnerability in Microsoft Windows Server.
Read more → -
ZDI-26-418: Microsoft SharePoint SPFieldMultiLineText Cross-Site Scripting Vulnerability
The advisory notes that SharePoint's SPFieldMultiLineText component is vulnerable to XSS that can be triggered by a malicious page or file.
Read more → -
ZDI-26-419: Adobe Creative Cloud AdobeUpdateService Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
The advisory notes a local privilege escalation via an uncontrolled search path element in AdobeUpdateService.
Read more → -
ZDI-26-420: Adobe Creative Cloud AGSService Incorrect Permission Assignment Local Privilege Escalation Vulnerability
The advisory notes that AGSService assigns incorrect permissions, allowing local privilege escalation.
Read more → -
ZDI-26-421: Cisco Identity Services Engine validFileNameOrPath Directory Traversal Information Disclosure Vulnerability
Remote authenticated attackers can exploit a directory traversal to disclose files on Cisco Identity Services Engine.
Read more → -
ZDI-26-422: Samsung rlottie Numeric Truncation Remote Code Execution Vulnerability
Remote code execution is possible via numeric truncation in Samsung rlottie.
Read more → -
ZDI-26-423: Synology DiskStation DS925+ MailPlus Redis Weak Cryptography for Passwords Remote Code Execution Vulnerability
Unauthenticated network-adjacent attackers can trigger remote code execution via the MailPlus Redis component on Synology DiskStation DS925+.
Read more → -
ZDI-26-424: Synology DiskStation DS925+ MailPlus Improper Restriction of Communication Channel to Intended Endpoints Vulnerability
Unauthenticated network-adjacent attackers can connect to the Redis service on DS925+ devices.
Read more → -
ZDI-26-425: OpenSSL OCSP Stapling Verification Double Free Remote Code Execution Vulnerability
OpenSSL’s OCSP stapling verification contains a double-free bug that can be triggered by a malicious server response.
Read more → -
ZDI-26-426: OpenSSL X.509 Email Validation Out-Of-Bounds Read Information Disclosure Vulnerability
The advisory notes an out-of-bounds read in OpenSSL’s X.509 email validation that can disclose information without authentication.
Read more → -
ZDI-26-427: WatchGuard FireWare OS iked ike2_hmac Null Pointer Dereference Denial-of-Service Vulnerability
Unauthenticated remote attackers can trigger a null-pointer dereference in the iked ike2_hmac function, causing a denial-of-service on WatchGuard FireWare OS VPN IKEv2.
Read more → -
ZDI-26-428: WatchGuard FireWare OS admd Stack-based Buffer Overflow Remote Code Execution Vulnerability
The admd service in WatchGuard FireWare OS has a stack-based buffer overflow that can be exploited remotely without authentication.
Read more → -
ZDI-26-429: NVIDIA NeMo Framework Deserialization of Untrusted Data Remote Code Execution Vulnerability
Exploitation requires the victim to load a malicious page or file.
Read more → -
ZDI-26-430: MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability
The vulnerability is a local privilege escalation in MSI Center's NTIOLib_X64 component.
Read more → -
ZDI-26-432: G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability
The advisory notes a local privilege escalation in G DATA Total Security (CVE-2026-13268).
Read more → -
ZDI-26-433: (Pwn2Own) Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability
Physical access enables arbitrary code execution on Autel MaxiCharger AC Elite Home EV chargers.
Read more → -
ZDI-26-434: (Pwn2Own) Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability
Physical attackers can bypass authentication on Autel MaxiCharger AC Elite Home EV chargers via USB.
Read more → -
ZDI-26-435: (Pwn2Own) Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability
A stack-based buffer overflow in the charger’s NFC stack can be triggered by a physically present attacker to execute code. No authentication is required.
Read more → -
ZDI-26-436: (Pwn2Own) Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability
Unauthenticated physical attackers can trigger a heap-based buffer overflow on Autel MaxiCharger AC Elite Home EV chargers.
Read more → -
ZDI-26-437: (Pwn2Own) Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability
Unauthenticated remote code execution via an integer underflow in the charger’s WebSockets interface. The issue affects Autel MaxiCharger AC Elite Home EV chargers.
Read more → -
ZDI-26-438: Rockwell Automation Arena Simulation DOE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
A crafted DOE file can cause an out-of-bounds write in Arena Simulation, enabling remote code execution after a user opens the file or visits a malicious page.
Read more → -
ZDI-26-439: Fuji Electric Tellus pcid64 Driver Exposed Dangerous Method Local Privilege Escalation Vulnerability
The advisory describes a local privilege escalation vulnerability in Fuji Electric Tellus pcid64 Driver. Attackers can escalate privileges after executing low-privileged code.
Read more → -
ZDI-26-440: Fuji Electric Tellus pcid64 Driver Untrusted Pointer Dereference Denial of Service Vulnerability
The pcid64 driver contains an untrusted pointer dereference that can cause a local denial-of-service.
Read more → -
ZDI-26-441: dnsmasq DNS Response Heap-based Buffer Overflow Remote Code Execution Vulnerability
dnsmasq contains a heap-based buffer overflow in DNS response handling that permits remote code execution without authentication.
Read more → -
ZDI-26-442: Linux Kernel CAN ISO-TP Protocol Race Condition Local Privilege Escalation Vulnerability
The advisory reports a race condition in the Linux kernel's CAN ISO-TP protocol implementation.
Read more → -
ZDI-26-443: Linux Kernel vmwgfx Integer Overflow Local Privilege Escalation Vulnerability
The issue is an integer overflow in the Linux kernel vmwgfx driver that enables local privilege escalation.
Read more → -
ZDI-26-404: Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability
Exploitation requires the victim to open a malicious file or visit a malicious page.
Read more → -
ZDI-26-398: (0Day) (Pwn2Own) Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability
Unauthenticated attackers on the same network can exploit a format-string flaw in the camera’s CDeviceOperator component to achieve remote code execution.
Read more → -
ZDI-26-399: (0Day) (Pwn2Own) Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability
Network-adjacent attackers can execute arbitrary code on Lorex 2K Indoor Wi-Fi cameras without user interaction.
Read more → -
ZDI-26-400: (0Day) AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability
AnyDesk installations are vulnerable to a local denial-of-service triggered via the screen-recording link feature.
Read more → -
ZDI-26-401: (0Day) AnyDesk Support Information Link Following Denial-of-Service Vulnerability
The vulnerability requires local code execution to trigger a denial-of-service condition via link following in AnyDesk.
Read more → -
ZDI-26-402: (0Day) Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability
The vulnerability involves link following in Glary Utilities that can lead to local privilege escalation.
Read more → -
ZDI-26-403: (0Day) Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability
Unauthenticated attackers can trigger a denial-of-service via the downloadBlob function.
Read more → -
ZDI-26-366: Fuji Electric Tellus pcid64 Driver File APIs Exposed Dangerous Method Arbitrary File Deletion Vulnerability
The vulnerability stems from exposed driver file APIs in Fuji Electric Tellus pcid64 that can be abused to delete arbitrary files.
Read more → -
ZDI-26-367: Fuji Electric Tellus pcid64 Driver Registry APIs Exposed Dangerous Method Local Privilege Escalation Vulnerability
The Fuji Electric Tellus pcid64 driver exposes registry APIs that can be exploited by local attackers for privilege escalation.
Read more → -
ZDI-26-368: Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability
The vulnerability involves a SQL injection in Quest NetVault Backup's NVBUDashboard that can lead to remote code execution, with authentication bypass possible.
Read more → -
ZDI-26-369: Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability
The vulnerability enables authentication bypass via cross-site scripting, requiring user interaction such as visiting a malicious page.
Read more → -
ZDI-26-370: Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability
The vulnerability involves an SQL injection in Quest NetVault Backup's NVBURASDevice that can lead to remote code execution, with authentication bypass possible.
Read more → -
ZDI-26-371: Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability
Authentication is required to exploit the vulnerability, but the advisory notes the authentication mechanism can be bypassed.
Read more → -
ZDI-26-372: Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability
Authentication is required to exploit the vulnerability, but the advisory notes the authentication mechanism can be bypassed.
Read more → -
ZDI-26-373: Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability
Authentication is required to exploit the vulnerability, but the advisory notes the authentication mechanism can be bypassed.
Read more → -
ZDI-26-374: Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability
Authentication is required to exploit the vulnerability, but the advisory notes the authentication mechanism can be bypassed.
Read more → -
ZDI-26-375: Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability
Authentication is required to exploit the vulnerability, but the advisory notes the authentication mechanism can be bypassed.
Read more → -
ZDI-26-376: Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability
Authentication is required to exploit the vulnerability, but the advisory notes the authentication mechanism can be bypassed.
Read more → -
ZDI-26-377: Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability
The vulnerability enables authentication bypass via cross-site scripting in Quest NetVault Backup's viewclient component, requiring user interaction.
Read more → -
ZDI-26-378: ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability
Authentication is required to exploit this directory traversal vulnerability leading to arbitrary file deletion in ATEN Unizon.
Read more → -
ZDI-26-379: ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability
Authentication is required to exploit this directory traversal vulnerability in ATEN Unizon's uploadSSL functionality.
Read more →
Page 2 of 5 · 489 advisories