Hackerzinc Zero Day - Upcoming

ZDI: Upcoming Advisories

The following is a list of vulnerabilities discovered by Zero Day Initiative researchers that are yet to be publicly disclosed. The affected vendor has been contacted on the specified date and while they work on a patch for these vulnerabilities, Trend Micro customers are protected from exploitation by IPS filters delivered ahead of public disclosure. Once the affected vendor patches the vulnerability, we publish an accompanying security advisory which describes the issue, including links to the vendor's fixes.

ZDI-CAN-25812: Apple 12.19.2024

A CVSS score 4.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N">AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-12-19, 11 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25587: QNAP 12.19.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Corentin "@OnlyTheDuck" BAYET from REverse Tactics' was reported to the affected vendor on: 2024-12-19, 11 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25953: Ivanti 12.19.2024

A CVSS score 7.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Kevin Salapatek' was reported to the affected vendor on: 2024-12-19, 11 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25681: Trend Micro 12.19.2024

A CVSS score 5.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a> severity vulnerability discovered by 'NT AUTHORITY\ANONYMOUS LOGON' was reported to the affected vendor on: 2024-12-19, 11 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25945: Ashlar-Vellum 12.19.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-12-19, 11 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25972: Ashlar-Vellum 12.19.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-12-19, 11 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25755: Ashlar-Vellum 12.19.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-12-19, 11 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25756: Ashlar-Vellum 12.19.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-12-19, 11 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25779: Canon 12.19.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'YingMuo (@YingMuo) working with DEVCORE Internship Program.' was reported to the affected vendor on: 2024-12-19, 11 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25862: Ashlar-Vellum 12.19.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-12-19, 11 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25710: Fortinet 12.19.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Alexander Staalgaard' was reported to the affected vendor on: 2024-12-19, 11 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25944: Ashlar-Vellum 12.19.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-12-19, 11 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25943: Ashlar-Vellum 12.19.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-12-19, 11 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25989: Autodesk 12.18.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-12-18, 12 days ago. The vendor is given until 2025-04-17 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25952: Autodesk 12.18.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-12-18, 12 days ago. The vendor is given until 2025-04-17 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25951: Autodesk 12.18.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-12-18, 12 days ago. The vendor is given until 2025-04-17 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25788: Oracle 12.18.2024

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Emad Al-Mousa' was reported to the affected vendor on: 2024-12-18, 12 days ago. The vendor is given until 2025-04-17 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25849: Lexmark 12.18.2024

A CVSS score 7.0 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'nella17 (@nella17tw), working with DEVCORE Internship Program, and DEVCORE Research Team' was reported to the affected vendor on: 2024-12-18, 12 days ago. The vendor is given until 2025-04-17 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-24122: Appleton 12.17.2024

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'kimiya' was reported to the affected vendor on: 2024-12-17, 13 days ago. The vendor is given until 2025-04-16 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25846: QNAP 12.13.2024

A CVSS score 5.0 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L">AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L</a> severity vulnerability discovered by 'nella17 (@nella17tw), working with DEVCORE Internship Program, and DEVCORE Research Team' was reported to the affected vendor on: 2024-12-13, 17 days ago. The vendor is given until 2025-04-12 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25847: QNAP 12.13.2024

A CVSS score 7.1 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'nella17 (@nella17tw), working with DEVCORE Internship Program, and DEVCORE Research Team' was reported to the affected vendor on: 2024-12-13, 17 days ago. The vendor is given until 2025-04-12 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25968: Autodesk 12.12.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Mat Powell of Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2024-12-12, 18 days ago. The vendor is given until 2025-04-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25971: Autodesk 12.12.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Mat Powell of Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2024-12-12, 18 days ago. The vendor is given until 2025-04-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25848: Lexmark 12.12.2024

A CVSS score 6.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L">AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a> severity vulnerability discovered by 'nella17 (@nella17tw), working with DEVCORE Internship Program, and DEVCORE Research Team' was reported to the affected vendor on: 2024-12-12, 18 days ago. The vendor is given until 2025-04-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25406: Delta Electronics 12.12.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'kimiya' was reported to the affected vendor on: 2024-12-12, 18 days ago. The vendor is given until 2025-04-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25970: Autodesk 12.12.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Mat Powell of Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2024-12-12, 18 days ago. The vendor is given until 2025-04-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25871: X.Org 12.11.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Jan-Niklas Sohn' was reported to the affected vendor on: 2024-12-11, 19 days ago. The vendor is given until 2025-04-10 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25740: X.Org 12.11.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Jan-Niklas Sohn' was reported to the affected vendor on: 2024-12-11, 19 days ago. The vendor is given until 2025-04-10 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25684: Adobe 12.11.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'AspiringYoungMan' was reported to the affected vendor on: 2024-12-11, 19 days ago. The vendor is given until 2025-04-10 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25870: X.Org 12.11.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Jan-Niklas Sohn' was reported to the affected vendor on: 2024-12-11, 19 days ago. The vendor is given until 2025-04-10 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25851: X.Org 12.11.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Jan-Niklas Sohn' was reported to the affected vendor on: 2024-12-11, 19 days ago. The vendor is given until 2025-04-10 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25791: Hewlett Packard Enterprise 12.11.2024

A CVSS score 7.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L">AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-12-11, 19 days ago. The vendor is given until 2025-04-10 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25629: Trend Micro 12.11.2024

A CVSS score 7.0 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-12-11, 19 days ago. The vendor is given until 2025-04-10 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25865: Sonos 12.11.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Cody Gallagher and Charlie Waters' was reported to the affected vendor on: 2024-12-11, 19 days ago. The vendor is given until 2025-04-10 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25872: Rockwell Automation 12.11.2024

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a> severity vulnerability discovered by 'Nikolai Skliarenko of Trend Micro Security Research' was reported to the affected vendor on: 2024-12-11, 19 days ago. The vendor is given until 2025-04-10 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25842: MedDream 12.10.2024

A CVSS score 5.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</a> severity vulnerability discovered by 'Chizuru Toyama of TXOne Networks' was reported to the affected vendor on: 2024-12-10, 20 days ago. The vendor is given until 2025-04-09 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25827: MedDream 12.10.2024

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Chizuru Toyama of TXOne Networks ' was reported to the affected vendor on: 2024-12-10, 20 days ago. The vendor is given until 2025-04-09 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25853: MedDream 12.10.2024

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Chizuru Toyama of TXOne Networks' was reported to the affected vendor on: 2024-12-10, 20 days ago. The vendor is given until 2025-04-09 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25825: MedDream 12.10.2024

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Chizuru Toyama of TXOne Networks' was reported to the affected vendor on: 2024-12-10, 20 days ago. The vendor is given until 2025-04-09 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25826: MedDream 12.10.2024

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Chizuru Toyama of TXOne Networks' was reported to the affected vendor on: 2024-12-10, 20 days ago. The vendor is given until 2025-04-09 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25711: Ivanti 12.6.2024

A CVSS score 7.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L">AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-12-06, 24 days ago. The vendor is given until 2025-04-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25876: Trend Micro 12.6.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vladislav Berghici of Trend Micro Research' was reported to the affected vendor on: 2024-12-06, 24 days ago. The vendor is given until 2025-04-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25712: Ivanti 12.6.2024

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-12-06, 24 days ago. The vendor is given until 2025-04-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25771: Trend Micro 12.6.2024

A CVSS score 6.7 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vladislav Berghici of Trend Micro Research' was reported to the affected vendor on: 2024-12-06, 24 days ago. The vendor is given until 2025-04-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25713: Ivanti 12.6.2024

A CVSS score 7.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L">AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-12-06, 24 days ago. The vendor is given until 2025-04-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25929: Ivanti 12.6.2024

A CVSS score 7.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Kevin Salapatek of Trend Micro Security Research' was reported to the affected vendor on: 2024-12-06, 24 days ago. The vendor is given until 2025-04-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25877: Trend Micro 12.6.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vladislav Berghici of Trend Micro Research' was reported to the affected vendor on: 2024-12-06, 24 days ago. The vendor is given until 2025-04-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25790: Hewlett Packard Enterprise 12.5.2024

A CVSS score 7.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L">AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-12-05, 25 days ago. The vendor is given until 2025-04-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25734: Adobe 12.5.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-12-05, 25 days ago. The vendor is given until 2025-04-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25789: Hewlett Packard Enterprise 12.5.2024

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-12-05, 25 days ago. The vendor is given until 2025-04-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25632: QNAP 12.2.2024

A CVSS score 6.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N">AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N</a> severity vulnerability discovered by 'Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam)' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25624: QNAP 12.2.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'PHP Hooligans / Midnight Blue' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25641: QNAP 12.2.2024

A CVSS score 8.0 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25737: Linux 12.2.2024

A CVSS score 9.0 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H">AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H</a> severity vulnerability discovered by 'Hexrabbit (@h3xr4bb1t) of DEVCORE Research Team' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25596: QNAP 12.2.2024

A CVSS score 5.0 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L">AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L</a> severity vulnerability discovered by 'Alain R\xc3\xb6del, Benjamin Walny (Neodyme AG)' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25633: QNAP 12.2.2024

A CVSS score 6.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L">AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a> severity vulnerability discovered by 'Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam)' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25631: QNAP 12.2.2024

A CVSS score 6.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N">AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N</a> severity vulnerability discovered by 'Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam)' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25530: QNAP 12.2.2024

A CVSS score 4.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N">AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</a> severity vulnerability discovered by 'Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam)' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25748: PDF-XChange 12.2.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25580: QNAP 12.2.2024

A CVSS score 8.1 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25634: QNAP 12.2.2024

A CVSS score 6.6 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam)' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25667: QNAP 12.2.2024

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Daan Keuper, Thijs Alkemade and Khaled Nassar from Computest Sector 7' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25645: QNAP 12.2.2024

A CVSS score 5.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</a> severity vulnerability discovered by '@quangnh89 and @ExLuck99' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25672: QNAP 12.2.2024

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Chris Anastasio @mufinnnnnnn & Fabius Watson' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25657: QNAP 12.2.2024

A CVSS score 8.1 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Benjamin Walny, Neodyme AG' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25585: QNAP 12.2.2024

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Corentin "@OnlyTheDuck" BAYET from REverse Tactics' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25536: QNAP 12.2.2024

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Team Viettel' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25635: QNAP 12.2.2024

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam)' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25653: QNAP 12.2.2024

A CVSS score 8.0 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Chris Anastasio @mufinnnnnnn & Fabius Watson' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25644: QNAP 12.2.2024

A CVSS score 5.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</a> severity vulnerability discovered by '@quangnh89 and @ExLuck99' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25483: QNAP 12.2.2024

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by '@quangnh89 and @ExLuck99' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25646: QNAP 12.2.2024

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by '@quangnh89 and @ExLuck99' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25656: QNAP 12.2.2024

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'YingMuo (@YingMuo), working with DEVCORE Internship Program.' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25612: QNAP 12.2.2024

A CVSS score 6.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L">AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a> severity vulnerability discovered by 'YingMuo (@YingMuo), working with DEVCORE Internship Program.' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25482: QNAP 12.2.2024

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Chris Anastasio @mufinnnnnnn & Fabius Watson' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25658: Synology 12.2.2024

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Pumpkin Chang (@u1f383) and Orange Tsai (@orange_8361) from DEVCORE Research Team' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25623: Synology 12.2.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'PHP Hooligans / Midnight Blue' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25659: Synology 12.2.2024

A CVSS score 6.4 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Pumpkin Chang (@u1f383) and Orange Tsai (@orange_8361) from DEVCORE Research Team' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25607: Synology 12.2.2024

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Jack Dates of RET2 Systems' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25403: Synology 12.2.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Ryan Emmons (Rapid7)' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25662: Synology 12.2.2024

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25538: Synology 12.2.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Team Viettel' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25613: Synology 12.2.2024

A CVSS score 6.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N">AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a> severity vulnerability discovered by 'Pumpkin Chang (@u1f383) and Orange Tsai (@orange_8361) from DEVCORE Research Team' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25539: Lexmark 12.2.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Team Viettel' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25487: Synology 12.2.2024

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Chris Anastasio @mufinnnnnnn & Fabius Watson' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25617: Synology 12.2.2024

A CVSS score 4.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N">AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25601: Sonos 12.2.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'InfoSect' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25606: Sonos 12.2.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Jack Dates of RET2 Systems' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25535: Sonos 12.2.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'dungdm (@_piers2) with Viettel Cyber Security' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25594: HP 12.2.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Felipe Jacob Custodio Romero, Neodyme AG' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25533: HP 12.2.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Team Viettel' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25647: Lorex 12.2.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'BoredPentester' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-24330: IBM 12.2.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-12-02, 28 days ago. The vendor is given until 2025-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25864: Realtek 11.21.2024

A CVSS score 3.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N">AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N</a> severity vulnerability discovered by 'dungnm from vcslab of Viettel Cyber Security' was reported to the affected vendor on: 2024-11-21, 39 days ago. The vendor is given until 2025-03-21 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25882: Autodesk 11.21.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vladislav Berghici of Trend Micro Research & Mat Powell of Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2024-11-21, 39 days ago. The vendor is given until 2025-03-21 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25811: Autodesk 11.21.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-11-21, 39 days ago. The vendor is given until 2025-03-21 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25700: Ashlar-Vellum 11.21.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-11-21, 39 days ago. The vendor is given until 2025-03-21 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25704: Ashlar-Vellum 11.21.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-11-21, 39 days ago. The vendor is given until 2025-03-21 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25869: Autodesk 11.21.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vladislav Berghici of Trend Micro Research & Mat Powell of Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2024-11-21, 39 days ago. The vendor is given until 2025-03-21 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25767: Autodesk 11.21.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-11-21, 39 days ago. The vendor is given until 2025-03-21 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25784: Autodesk 11.21.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-11-21, 39 days ago. The vendor is given until 2025-03-21 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25537: Lorex 11.20.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'phudq and namnp from Viettel Cyber Security' was reported to the affected vendor on: 2024-11-20, 40 days ago. The vendor is given until 2025-03-20 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25834: ServiceStack 11.19.2024

A CVSS score 5.9 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N">AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</a> severity vulnerability discovered by 'Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2024-11-19, 41 days ago. The vendor is given until 2025-03-19 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25837: ServiceStack 11.19.2024

A CVSS score 8.1 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2024-11-19, 41 days ago. The vendor is given until 2025-03-19 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25833: Siemens 11.19.2024

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a> severity vulnerability discovered by 'Jay Turla and Jerold Camacho of VicOne, Japz Divino of VikingCloud Inc.' was reported to the affected vendor on: 2024-11-19, 41 days ago. The vendor is given until 2025-03-19 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25049: Delta Electronics 11.19.2024

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-11-19, 41 days ago. The vendor is given until 2025-03-19 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-24786: Realtek 11.19.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'dungnm from vcslab of Viettel Cyber Security' was reported to the affected vendor on: 2024-11-19, 41 days ago. The vendor is given until 2025-03-19 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25794: NVIDIA 11.15.2024

A CVSS score 7.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L">AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a> severity vulnerability discovered by 'David Fiser and Alfredo Oliveira ( Nebula of Trend Micro )' was reported to the affected vendor on: 2024-11-15, 45 days ago. The vendor is given until 2025-03-15 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25683: X.Org 11.15.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Jan-Niklas Sohn' was reported to the affected vendor on: 2024-11-15, 45 days ago. The vendor is given until 2025-03-15 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25543: X.Org 11.15.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Jan-Niklas Sohn' was reported to the affected vendor on: 2024-11-15, 45 days ago. The vendor is given until 2025-03-15 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25544: X.Org 11.15.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Jan-Niklas Sohn' was reported to the affected vendor on: 2024-11-15, 45 days ago. The vendor is given until 2025-03-15 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25816: TeamViewer 11.15.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-11-15, 45 days ago. The vendor is given until 2025-03-15 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25495: Trend Micro 11.15.2024

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2024-11-15, 45 days ago. The vendor is given until 2025-03-15 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-23861: Viessmann 11.15.2024

A CVSS score 6.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'adhkr - LuwakLab' was reported to the affected vendor on: 2024-11-15, 45 days ago. The vendor is given until 2025-03-15 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25545: X.Org 11.15.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Jan-Niklas Sohn' was reported to the affected vendor on: 2024-11-15, 45 days ago. The vendor is given until 2025-03-15 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25637: iXsystems 11.15.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam)' was reported to the affected vendor on: 2024-11-15, 45 days ago. The vendor is given until 2025-03-15 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25636: iXsystems 11.15.2024

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam)' was reported to the affected vendor on: 2024-11-15, 45 days ago. The vendor is given until 2025-03-15 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25666: Ubiquiti Networks 11.15.2024

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Bongeun Koo(@kiddo_pwn), Dohyun Kim(@d0now), Junyoung Choi(@insp3ct0r_x), Wonbeen Im(@D0b6y), Juhyeop Lee(@leeju_04), Juyeong Lee(@ju_cheda), GuckHyeon Jin(@nang__lam), Jongmin Kim(@slyfizz3) of STEALIEN Inc.' was reported to the affected vendor on: 2024-11-15, 45 days ago. The vendor is given until 2025-03-15 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25603: Ubiquiti Networks 11.15.2024

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Bongeun Koo(@kiddo_pwn), Dohyun Kim(@d0now), Junyoung Choi(@insp3ct0r_x), Wonbeen Im(@D0b6y), Juhyeop Lee(@leeju_04), Juyeong Lee(@ju_cheda), GuckHyeon Jin(@nang__lam), Jongmin Kim(@slyfizz3) of STEALIEN Inc.' was reported to the affected vendor on: 2024-11-15, 45 days ago. The vendor is given until 2025-03-15 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25552: Ubiquiti Networks 11.15.2024

A CVSS score 8.1 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by '@ExLuck99' was reported to the affected vendor on: 2024-11-15, 45 days ago. The vendor is given until 2025-03-15 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25589: Ubiquiti Networks 11.15.2024

A CVSS score 6.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Synacktiv' was reported to the affected vendor on: 2024-11-15, 45 days ago. The vendor is given until 2025-03-15 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25674: Lexmark 11.15.2024

A CVSS score 4.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N">AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a> severity vulnerability discovered by 'Chris Anastasio @mufinnnnnnn & Fabius Watson' was reported to the affected vendor on: 2024-11-15, 45 days ago. The vendor is given until 2025-03-15 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25588: Ubiquiti Networks 11.15.2024

A CVSS score 9.6 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H">AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a> severity vulnerability discovered by 'Synacktiv' was reported to the affected vendor on: 2024-11-15, 45 days ago. The vendor is given until 2025-03-15 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25621: Lexmark 11.15.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'PHP Hooligans / Midnight Blue' was reported to the affected vendor on: 2024-11-15, 45 days ago. The vendor is given until 2025-03-15 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25676: Lexmark 11.15.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'PHP Hooligans / Midnight Blue' was reported to the affected vendor on: 2024-11-15, 45 days ago. The vendor is given until 2025-03-15 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25377: Python Packaging Authority 11.14.2024

A CVSS score 7.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-11-14, 46 days ago. The vendor is given until 2025-03-14 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-23950: CData 11.13.2024

A CVSS score 4.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N">AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</a> severity vulnerability discovered by 'adhkr - LuwakLab' was reported to the affected vendor on: 2024-11-13, 47 days ago. The vendor is given until 2025-03-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25808: Apple 11.13.2024

A CVSS score 3.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N">AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N</a> severity vulnerability discovered by 'Michael DePlante (@izobashi) of Trend Micro's Zero Day Initiative' was reported to the affected vendor on: 2024-11-13, 47 days ago. The vendor is given until 2025-03-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25678: PDF-XChange 11.13.2024

A CVSS score 3.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N">AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-11-13, 47 days ago. The vendor is given until 2025-03-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25443: Siemens 11.13.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-11-13, 47 days ago. The vendor is given until 2025-03-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25459: Ashlar-Vellum 11.13.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-11-13, 47 days ago. The vendor is given until 2025-03-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25477: Ashlar-Vellum 11.13.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-11-13, 47 days ago. The vendor is given until 2025-03-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25286: Trend Micro 11.13.2024

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-11-13, 47 days ago. The vendor is given until 2025-03-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25463: Ashlar-Vellum 11.13.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-11-13, 47 days ago. The vendor is given until 2025-03-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25481: Rockwell Automation 11.13.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-11-13, 47 days ago. The vendor is given until 2025-03-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25475: Ashlar-Vellum 11.13.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-11-13, 47 days ago. The vendor is given until 2025-03-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25695: Autodesk 11.13.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-11-13, 47 days ago. The vendor is given until 2025-03-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25430: npm 11.13.2024

A CVSS score 7.0 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-11-13, 47 days ago. The vendor is given until 2025-03-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25708: Progress Software 11.13.2024

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Nicholas Zubrisky (@NZubrisky) of Trend Micro Security Research' was reported to the affected vendor on: 2024-11-13, 47 days ago. The vendor is given until 2025-03-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25513: AzeoTech 11.13.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Andrea Micalizzi aka rgod (@rgod777)' was reported to the affected vendor on: 2024-11-13, 47 days ago. The vendor is given until 2025-03-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25515: AzeoTech 11.13.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Andrea Micalizzi aka rgod (@rgod777)' was reported to the affected vendor on: 2024-11-13, 47 days ago. The vendor is given until 2025-03-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25514: AzeoTech 11.13.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Andrea Micalizzi aka rgod (@rgod777)' was reported to the affected vendor on: 2024-11-13, 47 days ago. The vendor is given until 2025-03-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25521: AzeoTech 11.13.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Andrea Micalizzi aka rgod (@rgod777)' was reported to the affected vendor on: 2024-11-13, 47 days ago. The vendor is given until 2025-03-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25512: AzeoTech 11.13.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Andrea Micalizzi aka rgod (@rgod777)' was reported to the affected vendor on: 2024-11-13, 47 days ago. The vendor is given until 2025-03-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25511: AzeoTech 11.13.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Andrea Micalizzi aka rgod (@rgod777)' was reported to the affected vendor on: 2024-11-13, 47 days ago. The vendor is given until 2025-03-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25510: AzeoTech 11.13.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Andrea Micalizzi aka rgod (@rgod777)' was reported to the affected vendor on: 2024-11-13, 47 days ago. The vendor is given until 2025-03-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25465: Ashlar-Vellum 11.8.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-11-08, 52 days ago. The vendor is given until 2025-03-08 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25397: Mescius 11.8.2024

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2024-11-08, 52 days ago. The vendor is given until 2025-03-08 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25246: Mescius 11.8.2024

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by '06fe5fd2bc53027c4a3b7e395af0b850e7b8a044' was reported to the affected vendor on: 2024-11-08, 52 days ago. The vendor is given until 2025-03-08 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25761: Microsoft 11.8.2024

A CVSS score 7.0 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Simon Zuckerbraun - Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2024-11-08, 52 days ago. The vendor is given until 2025-03-08 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25661: Apple 11.7.2024

A CVSS score 3.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N">AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-11-07, 53 days ago. The vendor is given until 2025-03-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-24818: SonicWALL 11.5.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Daan Keuper, Thijs Alkemade and Khaled Nassar of Computest Security' was reported to the affected vendor on: 2024-11-05, 55 days ago. The vendor is given until 2025-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-24819: SonicWALL 11.5.2024

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Daan Keuper, Thijs Alkemade and Khaled Nassar of Computest Security' was reported to the affected vendor on: 2024-11-05, 55 days ago. The vendor is given until 2025-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-24820: SonicWALL 11.5.2024

A CVSS score 8.1 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N">AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</a> severity vulnerability discovered by 'Daan Keuper, Thijs Alkemade and Khaled Nassar of Computest Security' was reported to the affected vendor on: 2024-11-05, 55 days ago. The vendor is given until 2025-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-24821: SonicWALL 11.5.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Daan Keuper, Thijs Alkemade and Khaled Nassar of Computest Security' was reported to the affected vendor on: 2024-11-05, 55 days ago. The vendor is given until 2025-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25181: Fortinet 11.5.2024

A CVSS score 7.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Kentaro Kawane of GMO Cybersecurity by Ierae' was reported to the affected vendor on: 2024-11-05, 55 days ago. The vendor is given until 2025-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25369: Ivanti 11.5.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by '06fe5fd2bc53027c4a3b7e395af0b850e7b8a044' was reported to the affected vendor on: 2024-11-05, 55 days ago. The vendor is given until 2025-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25432: Ivanti 11.5.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by '06fe5fd2bc53027c4a3b7e395af0b850e7b8a044' was reported to the affected vendor on: 2024-11-05, 55 days ago. The vendor is given until 2025-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25736: Apple 11.5.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2024-11-05, 55 days ago. The vendor is given until 2025-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25570: Symantec 11.5.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by ' Vladislav Berghici of Trend Micro Research' was reported to the affected vendor on: 2024-11-05, 55 days ago. The vendor is given until 2025-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25735: Apple 11.5.2024

A CVSS score 3.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N">AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N</a> severity vulnerability discovered by 'Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2024-11-05, 55 days ago. The vendor is given until 2025-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25509: AVG 11.5.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vladislav Berghici of Trend Micro Research' was reported to the affected vendor on: 2024-11-05, 55 days ago. The vendor is given until 2025-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25549: Avast 11.5.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vladislav Berghici' was reported to the affected vendor on: 2024-11-05, 55 days ago. The vendor is given until 2025-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25448: GStreamer 11.5.2024

A CVSS score 7.0 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-11-05, 55 days ago. The vendor is given until 2025-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25682: NVIDIA 11.5.2024

A CVSS score 6.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L">AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L</a> severity vulnerability discovered by 'David Fiser and Alfredo Oliveira ( Nebula of Trend Micro )' was reported to the affected vendor on: 2024-11-05, 55 days ago. The vendor is given until 2025-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25424: Hugging Face 11.4.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'The_Kernel_Panic' was reported to the affected vendor on: 2024-11-04, 56 days ago. The vendor is given until 2025-03-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25689: Wacom 11.1.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Amol Dosanjh of Trend Micro' was reported to the affected vendor on: 2024-11-01, 59 days ago. The vendor is given until 2025-03-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-24984: Hewlett Packard Enterprise 10.31.2024

A CVSS score 7.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-10-31, 60 days ago. The vendor is given until 2025-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-24983: Hewlett Packard Enterprise 10.31.2024

A CVSS score 7.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-10-31, 60 days ago. The vendor is given until 2025-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-24981: Hewlett Packard Enterprise 10.31.2024

A CVSS score 7.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-10-31, 60 days ago. The vendor is given until 2025-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-24982: Hewlett Packard Enterprise 10.31.2024

A CVSS score 5.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N">AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-10-31, 60 days ago. The vendor is given until 2025-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25314: Hewlett Packard Enterprise 10.31.2024

A CVSS score 5.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-10-31, 60 days ago. The vendor is given until 2025-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-24985: Hewlett Packard Enterprise 10.31.2024

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-10-31, 60 days ago. The vendor is given until 2025-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25370: Apple 10.31.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Desmond' was reported to the affected vendor on: 2024-10-31, 60 days ago. The vendor is given until 2025-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25316: Hewlett Packard Enterprise 10.31.2024

A CVSS score 7.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-10-31, 60 days ago. The vendor is given until 2025-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25334: SolarWinds 10.31.2024

A CVSS score 7.1 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N">AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-10-31, 60 days ago. The vendor is given until 2025-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25187: Microsoft 10.31.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Jmini, Rotiple, D4m0n' was reported to the affected vendor on: 2024-10-31, 60 days ago. The vendor is given until 2025-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25319: Apple 10.31.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Pwn2car & Rotiple(HyeongSeok Jang)' was reported to the affected vendor on: 2024-10-31, 60 days ago. The vendor is given until 2025-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25524: Trend Micro 10.31.2024

A CVSS score 7.1 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N">AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N</a> severity vulnerability discovered by 'Abdessamad Lahlali and Smile Thanapattheerakul of Trend Micro' was reported to the affected vendor on: 2024-10-31, 60 days ago. The vendor is given until 2025-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25516: Amazon 10.31.2024

A CVSS score 6.6 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Yash Verma' was reported to the affected vendor on: 2024-10-31, 60 days ago. The vendor is given until 2025-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25557: PDF-XChange 10.31.2024

A CVSS score 3.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N">AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-10-31, 60 days ago. The vendor is given until 2025-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25476: Ashlar-Vellum 10.31.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-10-31, 60 days ago. The vendor is given until 2025-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25315: Hewlett Packard Enterprise 10.31.2024

A CVSS score 4.9 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2024-10-31, 60 days ago. The vendor is given until 2025-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25423: Hugging Face 10.16.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'The_Kernel_Panic' was reported to the affected vendor on: 2024-10-16, 75 days ago. The vendor is given until 2025-02-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25407: Delta Electronics 10.16.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Natnael Samson (@NattiSamson)' was reported to the affected vendor on: 2024-10-16, 75 days ago. The vendor is given until 2025-02-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25548: Avast 10.16.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by ' Vladislav Berghici of Trend Micro Research' was reported to the affected vendor on: 2024-10-16, 75 days ago. The vendor is given until 2025-02-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25180: Fortinet 10.16.2024

A CVSS score 6.6 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Kentaro Kawane of GMO Cybersecurity by Ierae' was reported to the affected vendor on: 2024-10-16, 75 days ago. The vendor is given until 2025-02-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25182: Fortinet 10.16.2024

A CVSS score 7.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Kentaro Kawane of GMO Cybersecurity by Ierae' was reported to the affected vendor on: 2024-10-16, 75 days ago. The vendor is given until 2025-02-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25559: Fortinet 10.16.2024

A CVSS score 5.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H</a> severity vulnerability discovered by 'Kentaro Kawane of GMO Cybersecurity by Ierae' was reported to the affected vendor on: 2024-10-16, 75 days ago. The vendor is given until 2025-02-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25039: Parallels 10.15.2024

A CVSS score 7.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Kolja Grassmann (Neodyme)' was reported to the affected vendor on: 2024-10-15, 76 days ago. The vendor is given until 2025-02-12 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25023: Cisco 10.15.2024

A CVSS score 4.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L">AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</a> severity vulnerability discovered by 'leg00m' was reported to the affected vendor on: 2024-10-15, 76 days ago. The vendor is given until 2025-02-12 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25218: Marvell 10.15.2024

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'kimiya' was reported to the affected vendor on: 2024-10-15, 76 days ago. The vendor is given until 2025-02-12 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25217: Marvell 10.15.2024

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'kimiya' was reported to the affected vendor on: 2024-10-15, 76 days ago. The vendor is given until 2025-02-12 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25576: Cisco 10.15.2024

A CVSS score 4.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L">AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</a> severity vulnerability discovered by 'leg00m' was reported to the affected vendor on: 2024-10-15, 76 days ago. The vendor is given until 2025-02-12 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25575: Cisco 10.15.2024

A CVSS score 4.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L">AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</a> severity vulnerability discovered by 'leg00m' was reported to the affected vendor on: 2024-10-15, 76 days ago. The vendor is given until 2025-02-12 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25577: Cisco 10.15.2024

A CVSS score 4.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L">AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</a> severity vulnerability discovered by 'leg00m' was reported to the affected vendor on: 2024-10-15, 76 days ago. The vendor is given until 2025-02-12 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25546: Apple 10.15.2024

A CVSS score 3.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L">AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L</a> severity vulnerability discovered by 'izo' was reported to the affected vendor on: 2024-10-15, 76 days ago. The vendor is given until 2025-02-12 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25188: Microsoft 10.15.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Jmini, Rotiple, D4m0n' was reported to the affected vendor on: 2024-10-15, 76 days ago. The vendor is given until 2025-02-12 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25526: Trend Micro 10.11.2024

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2024-10-11, 80 days ago. The vendor is given until 2025-02-08 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25473: PDF-XChange 10.11.2024

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2024-10-11, 80 days ago. The vendor is given until 2025-02-08 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.


© 1997-2024 hackerzinc
All rights reserved.