Radar
A personal hobby project. Radar aggregates security advisories from CISA, Zero Day Initiative and CERT-EU and adds short editorial highlights on what I find notable from a European infrastructure perspective — not a threat-intel service, not exhaustive, just what catches my eye.
-
ZDI-26-209: (Pwn2Own) Samsung Galaxy S25 Samsung Members Open Redirect Security Bypass Vulnerability
The advisory describes an open redirect vulnerability in Samsung Galaxy S25's Samsung Members component. The vulnerability allows bypassing security controls without requiring authentication.
Read more → -
ZDI-26-210: (Pwn2Own) Samsung Galaxy S25 Samsung Members Security Feature Bypass Vulnerability
The vulnerability enables remote security feature bypass on the Samsung Galaxy S25 without requiring authentication.
Read more → -
ZDI-26-211: Delta Electronics ASDA-Soft PAR File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
A stack-based buffer overflow exists in Delta Electronics ASDA-Soft's PAR file parsing. Exploitation requires user interaction through a malicious file or page.
Read more → -
ZDI-26-212: Schneider Electric EcoStruxure Data Center Expert Hard-coded Password Remote Code Execution Vulnerability
The advisory notes a hard-coded password vulnerability in Schneider Electric EcoStruxure Data Center Expert that allows remote code execution with authenticated access.
Read more → -
ZDI-26-213: GIMP LBM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
The vulnerability is triggered by parsing a malicious LBM file, leading to a heap-based buffer overflow.
Read more → -
ZDI-26-214: GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
The vulnerability is triggered by parsing malicious HDR files, leading to a heap-based buffer overflow in GIMP.
Read more → -
ZDI-26-215: KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
The vulnerability stems from an uncontrolled search path element in KeePassXC's OpenSSL configuration, potentially allowing local privilege escalation.
Read more → -
ZDI-26-173: Apple macOS Audio APAC Frame Decoding Out-Of-Bounds Write Remote Code Execution Vulnerability
The vulnerability involves an out-of-bounds write in the APAC frame decoding process within Apple macOS, potentially enabling remote code execution.
Read more → -
ZDI-26-174: Apple macOS ImageIO SGI File Parsing Integer Overflow Remote Code Execution Vulnerability
An integer overflow exists in Apple macOS ImageIO during SGI file parsing. The vulnerability requires interaction with the ImageIO library but specific attack vectors are not detailed.
Read more → -
ZDI-26-175: Apple macOS ImageIO SGI File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
The vulnerability requires interaction with macOS's ImageIO framework to exploit, but specific attack vectors depend on implementation.
Read more → -
ZDI-26-176: Apple macOS libusd_ms Alembic File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
The vulnerability involves an out-of-bounds write in libusd_ms during Alembic file parsing, requiring user interaction to trigger via a malicious file.
Read more → -
ZDI-26-177: Array Networks MotionPro ArrayInstallManager Incorrect Permission Assignment Local Privilege Escalation Vulnerability
MotionPro ArrayInstallManager has a local privilege escalation vulnerability requiring initial low-privileged code execution.
Read more → -
ZDI-26-178: Microsoft Windows cdd Improper Locking Local Privilege Escalation Vulnerability
The vulnerability resides in the Windows cdd component and requires prior code execution at a low-privileged level.
Read more → -
ZDI-26-179: Microsoft Windows win32kfull Improper Locking Local Privilege Escalation Vulnerability
This is a local privilege escalation vulnerability in Windows win32kfull requiring prior low-privileged code execution. The ZDI assigned a CVSS rating of 8.8.
Read more → -
ZDI-26-180: Microsoft Windows cdd Improper Locking Local Privilege Escalation Vulnerability
The vulnerability resides in the Windows cdd component and requires prior code execution at a low-privileged level to trigger improper locking conditions.
Read more → -
ZDI-26-181: Microsoft Windows win32full Improper Release Local Privilege Escalation Vulnerability
This vulnerability allows local privilege escalation in Microsoft Windows win32full component. Exploitation requires an attacker to already have code execution on the target system.
Read more → -
ZDI-26-182: Microsoft Windows win32full Improper Release Local Privilege Escalation Vulnerability
This vulnerability requires prior local code execution to exploit. The advisory assigns a CVSS score of 7.8.
Read more → -
ZDI-26-183: Microsoft Windows win32full Improper Release Local Privilege Escalation Vulnerability
This is a local privilege escalation vulnerability in Microsoft Windows win32full. Exploitation requires prior execution of low-privileged code on the target system.
Read more → -
ZDI-26-184: Microsoft Windows NDIS Driver Use-After-Free Local Privilege Escalation Vulnerability
This vulnerability requires local access for exploitation and targets the Windows NDIS driver.
Read more → -
ZDI-26-185: Microsoft Windows GDI Bitmap Parsing Out-Of-Bound Read Information Disclosure Vulnerability
This is an information disclosure vulnerability in Windows GDI bitmap parsing. Attack requires interaction with GDI library but specific attack vectors are not detailed.
Read more → -
ZDI-26-186: Fortinet FortiClient Link Following Local Privilege Escalation Vulnerability
The vulnerability involves link following in FortiClient that can lead to local privilege escalation when low-privileged code execution is already achieved.
Read more → -
ZDI-26-171: Unraid Update Request Path Traversal Remote Code Execution Vulnerability
The vulnerability requires authentication and involves a path traversal in the update request functionality of Unraid, potentially leading to remote code execution.
Read more → -
ZDI-26-172: Unraid Authentication Request Path Traversal Authentication Bypass Vulnerability
The advisory notes that authentication can be bypassed via a path traversal in the authentication request, with no authentication required to exploit.
Read more → -
ZDI-26-151: Delta Electronics CNCSoft-G2 DPAX File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
The vulnerability involves an out-of-bounds write in CNCSoft-G2 during DPAX file parsing, requiring user interaction for exploitation.
Read more → -
ZDI-26-152: Docker Desktop Docker Plugins Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
The vulnerability requires prior local code execution to escalate privileges. The advisory notes a CVSS score of 7.8 for this local privilege escalation.
Read more → -
ZDI-26-153: (Pwn2Own) Philips Hue Bridge Zigbee Stack Custom Command Handler Heap-based Buffer Overflow Remote Code Execution Vulnerability
The vulnerability requires user interaction during the device pairing process to trigger the heap-based buffer overflow in the Zigbee stack.
Read more → -
ZDI-26-154: (Pwn2Own) Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability
The vulnerability is a heap-based buffer overflow in the Philips Hue Bridge's HomeKit Pair-Setup process, exploitable without authentication.
Read more → -
ZDI-26-155: (Pwn2Own) Philips Hue Bridge hap_pair_verify_handler Sub-TLV Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
The vulnerability involves a heap-based buffer overflow in the hap_pair_verify_handler due to sub-TLV parsing on the Philips Hue Bridge.
Read more → -
ZDI-26-156: (Pwn2Own) Philips Hue Bridge HomeKit Accessory Protocol Transient Pairing Mode Authentication Bypass Vulnerability
This vulnerability allows network-adjacent attackers to bypass authentication on Philips Hue Bridge installations without requiring credentials.
Read more → -
ZDI-26-157: (Pwn2Own) Philips Hue Bridge HomeKit Accessory Protocol Static Nonce Authentication Bypass Vulnerability
The advisory notes a static nonce in the HomeKit Accessory Protocol can enable authentication bypass on Philips Hue Bridge.
Read more → -
ZDI-26-158: (Pwn2Own) Philips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerability
The vulnerability is a heap-based buffer overflow in the hk_hap_pair_storage_put function, exploitable remotely without authentication.
Read more → -
ZDI-26-159: (Pwn2Own) Philips Hue Bridge hk_hap characteristics Heap-based Buffer Overflow Remote Code Execution Vulnerability
Authentication is required to exploit the vulnerability, but the advisory notes the authentication mechanism can be bypassed.
Read more → -
ZDI-26-160: (Pwn2Own) Philips Hue Bridge hk_hap Ed25519 Signature Verification Authentication Bypass Vulnerability
The vulnerability affects Philips Hue Bridge and enables arbitrary code execution without authentication.
Read more → -
ZDI-26-161: GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability
The vulnerability is an out-of-bounds write in GStreamer's DVB subtitle parser, requiring interaction with the library but allowing arbitrary code execution.
Read more → -
ZDI-26-162: GStreamer H.266 Codec Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability
A stack-based buffer overflow exists in the GStreamer H.266 codec parser, which could allow remote code execution if exploited during media processing.
Read more → -
ZDI-26-163: GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability
The vulnerability is a heap-based buffer overflow in the GStreamer JPEG parser that may allow remote code execution.
Read more → -
ZDI-26-164: GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability
The vulnerability is a heap-based buffer overflow in the GStreamer ASF demuxer that may allow remote code execution.
Read more → -
ZDI-26-165: GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability
GStreamer RealMedia demuxer contains an out-of-bounds write vulnerability that may lead to remote code execution. Attack vectors depend on how applications implement the library.
Read more → -
ZDI-26-166: GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability
The vulnerability affects GStreamer's rtpqdm2depay component, allowing remote code execution via an out-of-bounds write. Attack vectors depend on how the library is implemented.
Read more → -
ZDI-26-167: GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability
The vulnerability is a heap-based buffer overflow in the GStreamer rtpqdm2depay element, which can lead to remote code execution.
Read more → -
ZDI-26-168: GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability
The vulnerability requires interaction with GStreamer library to trigger. Attack vectors vary based on implementation.
Read more → -
ZDI-26-169: GStreamer H.266 Codec Parser Integer Underflow Remote Code Execution Vulnerability
GStreamer H.266 parser contains an integer underflow vulnerability. The ZDI has assigned a CVSS rating of 7.8 for this remote code execution issue.
Read more → -
ZDI-26-170: GStreamer H.266 Codec Parser Out-Of-Bounds Write Remote Code Execution Vulnerability
The vulnerability is an out-of-bounds write in the GStreamer H.266 codec parser that could allow remote code execution.
Read more → -
ZDI-26-133: (Pwn2Own) Music Assistant _update_library_item External Control of File Path Remote Code Execution Vulnerability
The vulnerability involves external control of a file path in Music Assistant's _update_library_item function, enabling remote code execution without authentication.
Read more → -
ZDI-26-134: Hewlett Packard Enterprise AutoPass License Server Authentication Bypass Vulnerability
The vulnerability enables remote authentication bypass on HPE AutoPass License Server without requiring any credentials.
Read more → -
ZDI-26-135: LangChain LangGraph BaseCache Deserialization of Untrusted Data Remote Code Execution Vulnerability
The vulnerability involves deserialization of untrusted data in LangChain LangGraph, which could lead to remote code execution without authentication.
Read more → -
ZDI-26-136: Trend Micro Apex One Console Directory Traversal Remote Code Execution Vulnerability
The vulnerability permits remote code execution without authentication on Trend Micro Apex One Console via a directory traversal.
Read more → -
ZDI-26-137: Trend Micro Apex One Console Directory Traversal Remote Code Execution Vulnerability
The vulnerability does not require authentication, enabling unauthenticated remote attackers to exploit the condition.
Read more → -
ZDI-26-138: Trend Micro Apex One Virus Scan Engine Link Following Local Privilege Escalation Vulnerability
The vulnerability involves link following in the Trend Micro Apex One Virus Scan Engine, which may allow local privilege escalation under specific conditions.
Read more → -
ZDI-26-139: Trend Micro Apex One Security Agent iCore Service Origin Validation Error Local Privilege Escalation Vulnerability
The vulnerability requires local code execution as a precondition for privilege escalation. The advisory assigns a CVSS score of 7.8.
Read more → -
ZDI-26-140: Trend Micro Apex One Origin Validation Error Local Privilege Escalation Vulnerability
Local privilege escalation vulnerability in Trend Micro Apex One Security Agent requires initial access.
Read more → -
ZDI-26-141: Trend Micro Apex One Security Agent iCore Service Signature Verification Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability
The vulnerability involves a time-of-check time-of-use (TOCTOU) issue in the iCore Service's signature verification process, potentially allowing local privilege escalation.
Read more → -
ZDI-26-142: Trend Micro Apex One Security Agent Cache Mechanism Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability
The vulnerability requires an attacker to already have low-privileged code execution on the target system. The assigned CVSS score is 7.8.
Read more → -
ZDI-26-143: Trend Micro Apex One Security Agent TmSelfProtect Origin Validation Error Local Privilege Escalation Vulnerability
An origin validation error in the TmSelfProtect component allows local privilege escalation.
Read more → -
ZDI-26-144: Trend Micro Apex Central Hub Server Server-Side Request Forgery Vulnerability
The vulnerability requires authentication and could allow remote information disclosure via server-side request forgery.
Read more → -
ZDI-26-145: Trend Micro Apex Central Scheduled Update Server-Side Request Forgery Vulnerability
The vulnerability requires authentication and could allow remote information disclosure via server-side request forgery.
Read more → -
ZDI-26-146: Trend Micro Apex Central Manual Update Server-Side Request Forgery Vulnerability
The vulnerability requires authentication and could allow remote information disclosure via a server-side request forgery (SSRF) in Trend Micro Apex Central.
Read more → -
ZDI-26-147: Trend Micro Apex Central Improper Authentication Privilege Escalation Vulnerability
The vulnerability requires authentication before privilege escalation can occur in Trend Micro Apex Central.
Read more → -
ZDI-26-148: Trend Micro Apex Central Improper Authentication Privilege Escalation Vulnerability
The vulnerability requires authentication and allows privilege escalation in Trend Micro Apex Central.
Read more → -
ZDI-26-149: Trend Micro Cleaner One Pro Link Following Denial-of-Service Vulnerability
The vulnerability requires local execution of low-privileged code to trigger denial-of-service. The advisory notes a CVSS score of 5.0.
Read more → -
ZDI-26-150: Docker Desktop for Mac Docker Model Runner Exposed Dangerous Function Denial-of-Service Vulnerability
The vulnerability resides in Docker Desktop for Mac's Docker Model Runner, which exposes a function that can be triggered by local attackers to cause a denial-of-service condition.
Read more → -
2026-002: Multiple Vulnerabilities in Cisco Products
CVE-2026-20127 has been exploited in the wild since 2023. Cisco recommends capturing forensic evidence and hunting for indicators of compromise.
Read more → -
ZDI-26-124: claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability
The vulnerability in claude-hovercraft permits remote code execution via command injection without requiring authentication.
Read more → -
ZDI-26-125: Docker Desktop grpcfuse Kernel Module Out-Of-Bounds Read Information Disclosure Vulnerability
The vulnerability requires local execution of low-privileged code on a target system. It affects Docker Desktop's grpcfuse kernel module.
Read more → -
ZDI-26-126: (Pwn2Own) Ubiquiti Networks AI Pro Discovery Protocol Missing Encryption Protocol Downgrade Vulnerability
The advisory notes a protocol downgrade vulnerability in Ubiquiti Networks AI Pro's Discovery Protocol that can be exploited without authentication.
Read more → -
ZDI-26-127: (Pwn2Own) Ubiquiti Networks AI Pro Cleartext Transmission Information Disclosure Vulnerability
Ubiquiti AI Pro transmits sensitive information in cleartext without requiring authentication. Network-adjacent attackers can exploit this to disclose data.
Read more → -
ZDI-26-128: (Pwn2Own) Ubiquiti Networks AI Pro Uncaught Exception Denial-of-Service Vulnerability
Network-adjacent attackers can trigger denial-of-service without authentication. The vulnerability was demonstrated during Pwn2Own 2026.
Read more → -
ZDI-26-129: Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability
Network-adjacent attackers can bypass authentication on Socomec DIRIS A-40 power monitoring devices. The vulnerability does not require authentication to exploit.
Read more → -
ZDI-26-130: IceWarp collaboration Directory Traversal Information Disclosure Vulnerability
The vulnerability permits unauthenticated remote attackers to disclose sensitive information via a directory traversal flaw in IceWarp's collaboration component.
Read more → -
ZDI-26-131: Siemens SINEC NMS Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
The vulnerability stems from uncontrolled search path behavior in Siemens SINEC NMS, which may allow local privilege escalation if exploited.
Read more → -
ZDI-26-132: Siemens SINEC NMS Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
The vulnerability stems from uncontrolled search path behavior in Siemens SINEC NMS, allowing local privilege escalation when low-privileged code execution is already achieved.
Read more → -
ZDI-26-123: Docker Desktop MCP Server Cleartext Storage of Sensitive Information Vulnerability
Docker Desktop stores sensitive information in cleartext. Exploitation requires local code execution.
Read more → -
ZDI-26-108: Bosch Rexroth IndraWorks UA.TestClient XML File Parsing Deserialization Of Untrusted Data Remote Code Execution Vulnerability
The vulnerability requires user interaction via a malicious page or file to trigger remote code execution.
Read more → -
ZDI-26-109: Bosch Rexroth IndraWorks OPC.TestClient XML File Parsing Deserialization Of Untrusted Data Remote Code Execution Vulnerability
This vulnerability requires user interaction through a malicious file or page. The advisory assigns a CVSS rating of 7.8.
Read more → -
ZDI-26-110: Bosch Rexroth IndraWorks Print Settings File Parsing Deserialization Of Untrusted Data Remote Code Execution Vulnerability
The vulnerability requires user interaction, such as opening a malicious file or visiting a malicious page, to trigger remote code execution via deserialization of untrusted data.
Read more → -
ZDI-26-111: MLflow Use of Default Password Authentication Bypass Vulnerability
The advisory notes a default password authentication bypass in MLflow that does not require authentication to exploit.
Read more → -
ZDI-26-112: Dassault Systèmes eDrawings Viewer EPRT File Parsing Uninitialized Variable Remote Code Execution Vulnerability
The vulnerability stems from uninitialized variable usage during EPRT file parsing in eDrawings Viewer, requiring user interaction to trigger.
Read more → -
ZDI-26-113: Dassault Systèmes eDrawings Viewer EPRT File Parsing Memory Corruption Remote Code Execution Vulnerability
The vulnerability involves memory corruption during EPRT file parsing in eDrawings Viewer, requiring user interaction for exploitation.
Read more → -
ZDI-26-114: Dassault Systèmes eDrawings Viewer EPRT File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
The vulnerability involves an out-of-bounds write during EPRT file parsing, which could allow remote code execution if a user opens a malicious file.
Read more → -
ZDI-26-115: Fortinet FortiClient VPN FCConfig Utility Link Following Local Privilege Escalation Vulnerability
This vulnerability requires local code execution first, limiting its immediate impact.
Read more → -
ZDI-26-116: TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
The vulnerability requires local access and low-privileged code execution to exploit. The advisory notes a CVSS score of 7.0.
Read more → -
ZDI-26-117: RustDesk Client for Windows Transfer File Link Following Information Disclosure Vulnerability
A local attacker with low privileges can exploit this vulnerability to disclose sensitive information from RustDesk Client for Windows installations.
Read more → -
ZDI-26-118: GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability
The vulnerability stems from uninitialized memory usage during PGM file parsing in GIMP, which could lead to remote code execution if a user opens a malicious file.
Read more → -
ZDI-26-119: GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
The vulnerability involves an out-of-bounds write during XWD file parsing in GIMP, requiring user interaction to trigger.
Read more → -
ZDI-26-120: GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
The vulnerability is triggered by parsing a malicious ICNS file, leading to a heap-based buffer overflow in GIMP.
Read more → -
ZDI-26-121: GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
The vulnerability involves an out-of-bounds write during XWD file parsing in GIMP, which could allow remote code execution if a user opens a malicious file.
Read more → -
ZDI-26-122: PDF-XChange Editor TrackerUpdate Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
PDF-XChange Editor contains a local privilege escalation vulnerability in its TrackerUpdate component. Exploitation requires prior low-privileged code execution on the target system.
Read more → -
ZDI-26-106: Autodesk AutoCAD CATPART File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
The vulnerability involves an out-of-bounds write during CATPART file parsing in Autodesk AutoCAD, requiring user interaction for exploitation.
Read more → -
ZDI-26-107: Autodesk AutoCAD MODEL File Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability requires user interaction via opening a malicious file or visiting a malicious page.
Read more → -
ZDI-26-096: Dassault Systèmes eDrawings Viewer EPRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
The vulnerability requires user interaction via a malicious file or page. A heap-based buffer overflow enables remote code execution.
Read more → -
ZDI-26-097: Oracle VirtualBox VMSVGA Heap-based Buffer Overflow Local Privilege Escalation Vulnerability
The vulnerability requires prior execution of high-privileged code on the guest. The heap-based buffer overflow occurs in the VMSVGA component.
Read more → -
ZDI-26-098: Oracle VirtualBox VMSVGA Use-After-Free Local Privilege Escalation Vulnerability
This vulnerability requires prior high-privileged code execution on a guest system to escalate privileges. The ZDI assigned a CVSS rating of 8.2.
Read more → -
ZDI-26-099: Oracle VirtualBox VMSVGA Race Condition Local Privilege Escalation Vulnerability
Requires prior high-privileged code execution on the guest system. Exploitation is constrained to a race condition within the VMSVGA component.
Read more → -
ZDI-26-100: Oracle VirtualBox LsiLogic Uninitialized Memory Information Disclosure Vulnerability
The vulnerability requires a local attacker with high-privileged guest code execution to exploit. It targets Oracle VirtualBox's LsiLogic SCSI controller component.
Read more → -
ZDI-26-101: Oracle VirtualBox BusLogic Uninitialized Memory Information Disclosure Vulnerability
The vulnerability requires local execution of high-privileged code on a guest system. The CVSS rating is 6.0.
Read more → -
ZDI-26-102: Oracle VirtualBox VMSVGA Out-Of-Bounds Write Local Privilege Escalation Vulnerability
The vulnerability requires an attacker to already have high-privileged code execution on the guest system. The exploit targets the VirtualBox VMSVGA virtual device.
Read more → -
ZDI-26-103: Oracle VirtualBox VMSVGA Out-Of-Bounds Access Local Privilege Escalation Vulnerability
This vulnerability requires an attacker to already have high-privileged code execution on the guest system. The exploit targets the VMSVGA virtual graphics component within Oracle VirtualBox.
Read more → -
ZDI-26-104: Sante DICOM Viewer Pro DCM File Parsing Buffer Overflow Remote Code Execution Vulnerability
The vulnerability is triggered by parsing a malicious DCM file, requiring user interaction to open the file or visit a malicious page.
Read more → -
ZDI-26-105: MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability
The vulnerability affects the MLflow Tracking Server's Artifact Handler, allowing remote code execution via directory traversal without authentication.
Read more → -
2026-001: Critical vulnerabilities in Ivanti EPMM
One of the vulnerabilities has been exploited in a limited number of cases. The advisory addresses two critical vulnerabilities enabling unauthenticated remote code execution.
Read more →
Page 8 of 9 · 806 advisories