Hackerzinc Zero Day - Upcoming

ZDI: Upcoming Advisories

The following is a list of vulnerabilities discovered by Zero Day Initiative researchers that are yet to be publicly disclosed. The affected vendor has been contacted on the specified date and while they work on a patch for these vulnerabilities, Trend Micro customers are protected from exploitation by IPS filters delivered ahead of public disclosure. Once the affected vendor patches the vulnerability, we publish an accompanying security advisory which describes the issue, including links to the vendor's fixes.

ZDI-CAN-28176: Apple 12.5.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'George Karchemsky (@gkarchemsky)' was reported to the affected vendor on: 2025-12-05, 2 days ago. The vendor is given until 2026-04-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28487: Microsoft 12.5.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H">AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</a> severity vulnerability discovered by 'Marcin Wiazowski' was reported to the affected vendor on: 2025-12-05, 2 days ago. The vendor is given until 2026-04-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28381: Microsoft 12.5.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H">AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-12-05, 2 days ago. The vendor is given until 2026-04-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28486: QNAP 12.4.2025

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'gcali (@_gcali)' was reported to the affected vendor on: 2025-12-04, 3 days ago. The vendor is given until 2026-04-03 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28623: SolarWinds 12.4.2025

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Guy Lederfein of Trend Research' was reported to the affected vendor on: 2025-12-04, 3 days ago. The vendor is given until 2026-04-03 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28534: Linux 12.4.2025

A CVSS score 6.0 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N">AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N</a> severity vulnerability discovered by 'Syed Faraz Abrar (@farazsth98) from Zellic, and Pumpkin (@u1f383) from DEVCORE Research Team' was reported to the affected vendor on: 2025-12-04, 3 days ago. The vendor is given until 2026-04-03 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28553: Synology 12.4.2025

A CVSS score 3.1 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N">AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</a> severity vulnerability discovered by 'gcali (_gcali)' was reported to the affected vendor on: 2025-12-04, 3 days ago. The vendor is given until 2026-04-03 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28554: Synology 12.4.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'gcali (_gcali)' was reported to the affected vendor on: 2025-12-04, 3 days ago. The vendor is given until 2026-04-03 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28266: GIMP 12.4.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'MICHAEL RANDRIANANTENAINA [https://elkamika.blogspot.com/]' was reported to the affected vendor on: 2025-12-04, 3 days ago. The vendor is given until 2026-04-03 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28485: Synology 12.4.2025

A CVSS score 4.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N">AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a> severity vulnerability discovered by 'gcali (_gcali)' was reported to the affected vendor on: 2025-12-04, 3 days ago. The vendor is given until 2026-04-03 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28530: GIMP 12.4.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-12-04, 3 days ago. The vendor is given until 2026-04-03 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28447: Ashlar-Vellum 12.4.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2025-12-04, 3 days ago. The vendor is given until 2026-04-03 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28517: Krita 12.4.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Francis Provencher {PRL}' was reported to the affected vendor on: 2025-12-04, 3 days ago. The vendor is given until 2026-04-03 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28594: Linux 12.4.2025

A CVSS score 6.0 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N">AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N</a> severity vulnerability discovered by 'Lucas Leong (@_wmliang_) of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-12-04, 3 days ago. The vendor is given until 2026-04-03 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28260: Microsoft 12.3.2025

A CVSS score 6.7 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Nelson William Gamazo Sanchez and Nitesh Surana (niteshsurana.com) of Trend Research' was reported to the affected vendor on: 2025-12-03, 4 days ago. The vendor is given until 2026-04-02 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28271: Microsoft 12.2.2025

A CVSS score 3.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N">AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-12-02, 5 days ago. The vendor is given until 2026-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28247: Microsoft 12.2.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a> severity vulnerability discovered by 'Marcin Wiazowski' was reported to the affected vendor on: 2025-12-02, 5 days ago. The vendor is given until 2026-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28498: Microsoft 12.2.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H">AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</a> severity vulnerability discovered by 'Marcin Wiazowski' was reported to the affected vendor on: 2025-12-02, 5 days ago. The vendor is given until 2026-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28557: Microsoft 12.2.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a> severity vulnerability discovered by 'Marcin Wiazowski' was reported to the affected vendor on: 2025-12-02, 5 days ago. The vendor is given until 2026-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28488: Microsoft 12.2.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H">AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</a> severity vulnerability discovered by 'Marcin Wiazowski' was reported to the affected vendor on: 2025-12-02, 5 days ago. The vendor is given until 2026-04-01 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28044: VMware 11.27.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a> severity vulnerability discovered by 'awxylitol' was reported to the affected vendor on: 2025-11-27, 10 days ago. The vendor is given until 2026-03-27 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28570: pdfforge 11.27.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'soiax' was reported to the affected vendor on: 2025-11-27, 10 days ago. The vendor is given until 2026-03-27 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28558: Foxit 11.27.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-11-27, 10 days ago. The vendor is given until 2026-03-27 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-26885: Ivanti 11.25.2025

A CVSS score 8.6 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N">AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N</a> severity vulnerability discovered by '06fe5fd2bc53027c4a3b7e395af0b850e7b8a044' was reported to the affected vendor on: 2025-11-25, 12 days ago. The vendor is given until 2026-03-25 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28617: Ivanti 11.25.2025

A CVSS score 4.9 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N</a> severity vulnerability discovered by '06fe5fd2bc53027c4a3b7e395af0b850e7b8a044' was reported to the affected vendor on: 2025-11-25, 12 days ago. The vendor is given until 2026-03-25 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27424: Hugging Face 11.25.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-11-25, 12 days ago. The vendor is given until 2026-03-25 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28388: MindsDB 11.20.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Peter Girnus (@gothburz), Demeng Chen, and Brandon Niemczyk of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-11-20, 17 days ago. The vendor is given until 2026-03-20 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28552: Apple 11.19.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Michael DePlante (@izobashi) of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-11-19, 18 days ago. The vendor is given until 2026-03-19 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27935: GFI 11.19.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-11-19, 18 days ago. The vendor is given until 2026-03-19 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27628: QEMU 11.19.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a> severity vulnerability discovered by 'Xiaobye(@xiaobye_tw) of DEVCORE Research Team' was reported to the affected vendor on: 2025-11-19, 18 days ago. The vendor is given until 2026-03-19 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28597: GFI 11.19.2025

A CVSS score 7.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L">AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-11-19, 18 days ago. The vendor is given until 2026-03-19 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27934: GFI 11.19.2025

A CVSS score 7.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L">AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-11-19, 18 days ago. The vendor is given until 2026-03-19 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28569: Vim 11.19.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Simon Zuckerbraun of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-11-19, 18 days ago. The vendor is given until 2026-03-19 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27936: GFI 11.19.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-11-19, 18 days ago. The vendor is given until 2026-03-19 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28490: Linux 11.18.2025

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a> severity vulnerability discovered by 'Maher Azzouzi (@maherazz2)' was reported to the affected vendor on: 2025-11-18, 19 days ago. The vendor is given until 2026-03-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28190: Docker 11.14.2025

A CVSS score 6.7 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Nitesh Surana (niteshsurana.com) and Amol Dosanjh of Trend Research' was reported to the affected vendor on: 2025-11-14, 23 days ago. The vendor is given until 2026-03-14 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28410: Microsoft 11.14.2025

A CVSS score 5.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N">AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</a> severity vulnerability discovered by 'Vladislav Berghici of Trend Research' was reported to the affected vendor on: 2025-11-14, 23 days ago. The vendor is given until 2026-03-14 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28462: Microsoft 11.14.2025

A CVSS score 5.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N">AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</a> severity vulnerability discovered by 'Vladislav Berghici of Trend Research' was reported to the affected vendor on: 2025-11-14, 23 days ago. The vendor is given until 2026-03-14 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28542: Docker 11.14.2025

A CVSS score 6.7 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Nitesh Surana (niteshsurana.com) and Amol Dosanjh of Trend Research' was reported to the affected vendor on: 2025-11-14, 23 days ago. The vendor is given until 2026-03-14 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28101: Qwen 11.11.2025

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Peter Girnus (@gothburz) and Brandon Niemczyk of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-11-11, 26 days ago. The vendor is given until 2026-03-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28232: GIMP 11.11.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-11-11, 26 days ago. The vendor is given until 2026-03-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28172: Ashlar-Vellum 11.11.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2025-11-11, 26 days ago. The vendor is given until 2026-03-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28173: Ashlar-Vellum 11.11.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2025-11-11, 26 days ago. The vendor is given until 2026-03-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28248: GIMP 11.11.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-11-11, 26 days ago. The vendor is given until 2026-03-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28376: GIMP 11.11.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-11-11, 26 days ago. The vendor is given until 2026-03-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28416: GIMP 11.11.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-11-11, 26 days ago. The vendor is given until 2026-03-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28405: GIMP 11.11.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-11-11, 26 days ago. The vendor is given until 2026-03-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28273: GIMP 11.11.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-11-11, 26 days ago. The vendor is given until 2026-03-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28158: GIMP 11.11.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-11-11, 26 days ago. The vendor is given until 2026-03-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28311: GIMP 11.11.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-11-11, 26 days ago. The vendor is given until 2026-03-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28265: GIMP 11.11.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'MICHAEL RANDRIANANTENAINA [https://elkamika.blogspot.com/]' was reported to the affected vendor on: 2025-11-11, 26 days ago. The vendor is given until 2026-03-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28159: Microsoft 11.7.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a> severity vulnerability discovered by 'Marcin Wiazowski' was reported to the affected vendor on: 2025-11-07, 30 days ago. The vendor is given until 2026-03-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28491: Microsoft 11.7.2025

A CVSS score 3.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N">AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N</a> severity vulnerability discovered by 'Jonathan Lein of Trend Research' was reported to the affected vendor on: 2025-11-07, 30 days ago. The vendor is given until 2026-03-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28529: llama.cpp 11.6.2025

A CVSS score 4.0 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N">AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</a> severity vulnerability discovered by 'Nitesh Surana (niteshsurana.com) of Trend Research' was reported to the affected vendor on: 2025-11-06, 31 days ago. The vendor is given until 2026-03-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28421: Autodesk 11.6.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2025-11-06, 31 days ago. The vendor is given until 2026-03-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28417: Autodesk 11.6.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2025-11-06, 31 days ago. The vendor is given until 2026-03-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28299: ALGO 11.5.2025

A CVSS score 5.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N">AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a> severity vulnerability discovered by 'Vera Mensa of Claroty Research - Team82' was reported to the affected vendor on: 2025-11-05, 32 days ago. The vendor is given until 2026-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28081: Apple 11.5.2025

A CVSS score 3.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N">AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N</a> severity vulnerability discovered by 'George Karchemsky (@gkarchemsky)' was reported to the affected vendor on: 2025-11-05, 32 days ago. The vendor is given until 2026-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28379: Docker 11.5.2025

A CVSS score 7.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H">AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H</a> severity vulnerability discovered by 'Nitesh Surana (niteshsurana.com) of Trend Research' was reported to the affected vendor on: 2025-11-05, 32 days ago. The vendor is given until 2026-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28477: Lexmark 11.5.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Interrupt Labs' was reported to the affected vendor on: 2025-11-05, 32 days ago. The vendor is given until 2026-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27899: JumpCloud 11.5.2025

A CVSS score 6.7 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Hillel Pinto' was reported to the affected vendor on: 2025-11-05, 32 days ago. The vendor is given until 2026-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28382: ByteDance 11.5.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Peter Girnus (@gothburz), Demeng Chen, and Brandon Niemczyk of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-11-05, 32 days ago. The vendor is given until 2026-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28523: Foxit 11.4.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Mat Powell of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-11-04, 33 days ago. The vendor is given until 2026-03-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28378: Dassault Systèmes 11.4.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-11-04, 33 days ago. The vendor is given until 2026-03-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28315: Dassault Systèmes 11.4.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-11-04, 33 days ago. The vendor is given until 2026-03-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28306: Foxit 11.4.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-11-04, 33 days ago. The vendor is given until 2026-03-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28403: Foxit 11.4.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'KX.H' was reported to the affected vendor on: 2025-11-04, 33 days ago. The vendor is given until 2026-03-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28404: Dassault Systèmes 11.4.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-11-04, 33 days ago. The vendor is given until 2026-03-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28532: Foxit 11.4.2025

A CVSS score 3.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N">AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N</a> severity vulnerability discovered by 'Mat Powell of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-11-04, 33 days ago. The vendor is given until 2026-03-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28531: Foxit 11.4.2025

A CVSS score 3.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N">AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N</a> severity vulnerability discovered by 'Mat Powell of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-11-04, 33 days ago. The vendor is given until 2026-03-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28302: ALGO 10.31.2025

A CVSS score 8.1 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vera Mensa of Claroty Research - Team82' was reported to the affected vendor on: 2025-10-31, 37 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28321: ALGO 10.31.2025

A CVSS score 7.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vera Mensa of Claroty Research - Team82' was reported to the affected vendor on: 2025-10-31, 37 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28303: ALGO 10.31.2025

A CVSS score 8.1 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vera Mensa of Claroty Research - Team82' was reported to the affected vendor on: 2025-10-31, 37 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-25568: ALGO 10.31.2025

A CVSS score 7.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vera Mensa of Claroty Research - Team82' was reported to the affected vendor on: 2025-10-31, 37 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28298: ALGO 10.31.2025

A CVSS score 5.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N">AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</a> severity vulnerability discovered by 'Vera Mensa of Claroty Research - Team82' was reported to the affected vendor on: 2025-10-31, 37 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28301: ALGO 10.31.2025

A CVSS score 8.1 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vera Mensa of Claroty Research - Team82' was reported to the affected vendor on: 2025-10-31, 37 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28293: ALGO 10.31.2025

A CVSS score 7.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vera Mensa of Claroty Research - Team82' was reported to the affected vendor on: 2025-10-31, 37 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28289: ALGO 10.31.2025

A CVSS score 7.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vera Mensa of Claroty Research - Team82' was reported to the affected vendor on: 2025-10-31, 37 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28297: ALGO 10.31.2025

A CVSS score 5.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N">AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a> severity vulnerability discovered by 'Vera Mensa of Claroty Research - Team82' was reported to the affected vendor on: 2025-10-31, 37 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28300: ALGO 10.31.2025

A CVSS score 8.1 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vera Mensa of Claroty Research - Team82' was reported to the affected vendor on: 2025-10-31, 37 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28322: ALGO 10.31.2025

A CVSS score 7.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vera Mensa of Claroty Research - Team82' was reported to the affected vendor on: 2025-10-31, 37 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28295: ALGO 10.31.2025

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vera Mensa of Claroty Research - Team82' was reported to the affected vendor on: 2025-10-31, 37 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28296: ALGO 10.31.2025

A CVSS score 8.1 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vera Mensa of Claroty Research - Team82' was reported to the affected vendor on: 2025-10-31, 37 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28292: ALGO 10.31.2025

A CVSS score 7.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vera Mensa of Claroty Research - Team82' was reported to the affected vendor on: 2025-10-31, 37 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28294: ALGO 10.31.2025

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vera Mensa of Claroty Research - Team82' was reported to the affected vendor on: 2025-10-31, 37 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28290: ALGO 10.31.2025

A CVSS score 7.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vera Mensa of Claroty Research - Team82' was reported to the affected vendor on: 2025-10-31, 37 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28291: ALGO 10.31.2025

A CVSS score 7.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vera Mensa of Claroty Research - Team82' was reported to the affected vendor on: 2025-10-31, 37 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28212: Flowise 10.30.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Nicholas Zubrisky (@NZubrisky) of Trend Research' was reported to the affected vendor on: 2025-10-30, 38 days ago. The vendor is given until 2026-02-27 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27594: Progress Software 10.29.2025

A CVSS score 7.1 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Alex Williams from Converge Technology Solutions' was reported to the affected vendor on: 2025-10-29, 39 days ago. The vendor is given until 2026-02-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27596: Progress Software 10.29.2025

A CVSS score 6.4 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Alex Williams from Converge Technology Solutions' was reported to the affected vendor on: 2025-10-29, 39 days ago. The vendor is given until 2026-02-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27884: Trend Micro 10.29.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Lays (@_L4ys) of TRAPA Security' was reported to the affected vendor on: 2025-10-29, 39 days ago. The vendor is given until 2026-02-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27582: Trend Micro 10.29.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-10-29, 39 days ago. The vendor is given until 2026-02-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28131: Deciso 10.29.2025

A CVSS score 6.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Alex Williams from Pellera Technologies' was reported to the affected vendor on: 2025-10-29, 39 days ago. The vendor is given until 2026-02-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28216: Airbyte 10.29.2025

A CVSS score 7.7 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N">AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N</a> severity vulnerability discovered by 'Peter Girnus (@gothburz) and Brandon Niemczyk of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-10-29, 39 days ago. The vendor is given until 2026-02-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27898: JumpCloud 10.29.2025

A CVSS score 5.0 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H">AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H</a> severity vulnerability discovered by 'Hillel Pinto' was reported to the affected vendor on: 2025-10-29, 39 days ago. The vendor is given until 2026-02-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28061: Trend Micro 10.29.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Lays (@_L4ys) of TRAPA Security' was reported to the affected vendor on: 2025-10-29, 39 days ago. The vendor is given until 2026-02-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28215: Airbyte 10.29.2025

A CVSS score 7.7 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N">AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N</a> severity vulnerability discovered by 'Peter Girnus (@gothburz) and Brandon Niemczyk of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-10-29, 39 days ago. The vendor is given until 2026-02-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27593: Progress Software 10.29.2025

A CVSS score 7.1 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Alex Williams from Converge Technology Solutions' was reported to the affected vendor on: 2025-10-29, 39 days ago. The vendor is given until 2026-02-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27591: Progress Software 10.29.2025

A CVSS score 6.4 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Alex Williams from Converge Technology Solutions' was reported to the affected vendor on: 2025-10-29, 39 days ago. The vendor is given until 2026-02-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28387: CrewAI 10.29.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Peter Girnus (@gothburz), Demeng Chen, and Brandon Niemczyk of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-10-29, 39 days ago. The vendor is given until 2026-02-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27581: Fortinet 10.29.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Febin Mon Saji from Astra Security' was reported to the affected vendor on: 2025-10-29, 39 days ago. The vendor is given until 2026-02-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27896: Trend Micro 10.29.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Lays (@_L4ys) of TRAPA Security' was reported to the affected vendor on: 2025-10-29, 39 days ago. The vendor is given until 2026-02-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27959: Trend Micro 10.29.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Lays (@_L4ys) of TRAPA Security' was reported to the affected vendor on: 2025-10-29, 39 days ago. The vendor is given until 2026-02-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28118: Trend Micro 10.29.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Lays (@_L4ys) of TRAPA Security' was reported to the affected vendor on: 2025-10-29, 39 days ago. The vendor is given until 2026-02-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28089: Trend Micro 10.29.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Lays (@_L4ys) of TRAPA Security' was reported to the affected vendor on: 2025-10-29, 39 days ago. The vendor is given until 2026-02-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28077: Trend Micro 10.29.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Lays (@_L4ys) of TRAPA Security' was reported to the affected vendor on: 2025-10-29, 39 days ago. The vendor is given until 2026-02-26 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27882: Un4seen Developments 10.24.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'SeoIn Yeo (Seoring) of Vulnerable Potatoes' was reported to the affected vendor on: 2025-10-24, 44 days ago. The vendor is given until 2026-02-21 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28304: Docker 10.16.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Nitesh Surana (niteshsurana.com) of Trend Research' was reported to the affected vendor on: 2025-10-16, 52 days ago. The vendor is given until 2026-02-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28284: Apple 10.15.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Hossein Lotfi (@hosselot) of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-10-15, 53 days ago. The vendor is given until 2026-02-12 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28285: Apple 10.15.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Hossein Lotfi (@hosselot) of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-10-15, 53 days ago. The vendor is given until 2026-02-12 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27578: QEMU 10.15.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a> severity vulnerability discovered by 'Xiaobye(@xiaobye_tw) of DEVCORE Research Team' was reported to the affected vendor on: 2025-10-15, 53 days ago. The vendor is given until 2026-02-12 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27595: Progress Software 10.15.2025

A CVSS score 6.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Alex Williams from Converge Technology Solutions' was reported to the affected vendor on: 2025-10-15, 53 days ago. The vendor is given until 2026-02-12 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28256: MLflow 10.14.2025

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Peter Girnus (@gothburz) of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-10-14, 54 days ago. The vendor is given until 2026-02-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28252: Hugging Face 10.14.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Peter Girnus (@gothburz), Brandon Niemczyk of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-10-14, 54 days ago. The vendor is given until 2026-02-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28253: Hugging Face 10.14.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Peter Girnus (@gothburz), Brandon Niemczyk of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-10-14, 54 days ago. The vendor is given until 2026-02-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28251: Hugging Face 10.14.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Peter Girnus (@gothburz), Brandon Niemczyk of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-10-14, 54 days ago. The vendor is given until 2026-02-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28066: Microsoft 10.13.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a> severity vulnerability discovered by 'Marcin Wiazowski' was reported to the affected vendor on: 2025-10-13, 55 days ago. The vendor is given until 2026-02-10 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28211: Fortinet 10.10.2025

A CVSS score 8.1 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Jason McFadyen of Trend Research' was reported to the affected vendor on: 2025-10-10, 58 days ago. The vendor is given until 2026-02-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28082: Microsoft 10.10.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-10-10, 58 days ago. The vendor is given until 2026-02-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27673: Fuji Electric 10.9.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by '\xea\xb9\x80\xeb\xaa\x85\xea\xb7\x9c' was reported to the affected vendor on: 2025-10-09, 59 days ago. The vendor is given until 2026-02-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28259: Open WebUI 10.9.2025

A CVSS score 5.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</a> severity vulnerability discovered by 'Peter Girnus (@gothburz), Brandon Niemczyk of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-10-09, 59 days ago. The vendor is given until 2026-02-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27744: Fuji Electric 10.9.2025

A CVSS score 5.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a> severity vulnerability discovered by '\xea\xb9\x80\xeb\xaa\x85\xea\xb7\x9c' was reported to the affected vendor on: 2025-10-09, 59 days ago. The vendor is given until 2026-02-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27996: Bosch Rexroth 10.9.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'kimiya' was reported to the affected vendor on: 2025-10-09, 59 days ago. The vendor is given until 2026-02-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28079: Oracle 10.9.2025

A CVSS score 6.0 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N">AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N</a> severity vulnerability discovered by 'PhuDQ from Viettel Cybersecurity' was reported to the affected vendor on: 2025-10-09, 59 days ago. The vendor is given until 2026-02-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27994: Bosch Rexroth 10.9.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'kimiya' was reported to the affected vendor on: 2025-10-09, 59 days ago. The vendor is given until 2026-02-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28255: All Hands 10.9.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Peter Girnus (@gothburz), Brandon Niemczyk of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-10-09, 59 days ago. The vendor is given until 2026-02-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28258: Open WebUI 10.9.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Peter Girnus (@gothburz), Brandon Niemczyk of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-10-09, 59 days ago. The vendor is given until 2026-02-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28080: Oracle 10.9.2025

A CVSS score 6.0 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N">AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N</a> severity vulnerability discovered by 'Viettel Cyber Security' was reported to the affected vendor on: 2025-10-09, 59 days ago. The vendor is given until 2026-02-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28210: Foxit 10.9.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-10-09, 59 days ago. The vendor is given until 2026-02-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28112: Bosch Rexroth 10.9.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'kimiya' was reported to the affected vendor on: 2025-10-09, 59 days ago. The vendor is given until 2026-02-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28257: Open WebUI 10.9.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Peter Girnus (@gothburz), Brandon Niemczyk of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-10-09, 59 days ago. The vendor is given until 2026-02-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27868: Trend Micro 10.8.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Lays (@_L4ys) of TRAPA Security' was reported to the affected vendor on: 2025-10-08, 60 days ago. The vendor is given until 2026-02-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27835: Microsoft 10.8.2025

A CVSS score 4.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L">AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L</a> severity vulnerability discovered by 'sumin' was reported to the affected vendor on: 2025-10-08, 60 days ago. The vendor is given until 2026-02-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28250: Nagios 10.8.2025

A CVSS score 7.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vladislav Berghici of Trend Research' was reported to the affected vendor on: 2025-10-08, 60 days ago. The vendor is given until 2026-02-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27999: Trend Micro 10.8.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Xavier DANEST - Decathlon' was reported to the affected vendor on: 2025-10-08, 60 days ago. The vendor is given until 2026-02-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28249: Nagios 10.8.2025

A CVSS score 7.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vladislav Berghici of Trend Research' was reported to the affected vendor on: 2025-10-08, 60 days ago. The vendor is given until 2026-02-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28236: Allegra 10.8.2025

A CVSS score 4.6 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N">AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N</a> severity vulnerability discovered by ' Bobby Gould (@bobbygould5) of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-10-08, 60 days ago. The vendor is given until 2026-02-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28245: Nagios 10.8.2025

A CVSS score 7.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Vladislav Berghici of Trend Research' was reported to the affected vendor on: 2025-10-08, 60 days ago. The vendor is given until 2026-02-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27877: Framelink 10.7.2025

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Peter Girnus (@gothburz) and Brandon Niemczyk of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-10-07, 61 days ago. The vendor is given until 2026-02-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28254: All Hands 10.7.2025

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Peter Girnus (@gothburz), Brandon Niemczyk of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-10-07, 61 days ago. The vendor is given until 2026-02-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28053: Foxit 10.7.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'kozmer' was reported to the affected vendor on: 2025-10-07, 61 days ago. The vendor is given until 2026-02-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28198: FontForge 10.7.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by ' volticks (@movx64 on twitter) ' was reported to the affected vendor on: 2025-10-07, 61 days ago. The vendor is given until 2026-02-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28186: Dassault Systèmes 10.7.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-10-07, 61 days ago. The vendor is given until 2026-02-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28188: Dassault Systèmes 10.7.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-10-07, 61 days ago. The vendor is given until 2026-02-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27785: claude-hovercraft 10.6.2025

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Peter Girnus (@gothburz) of Trend Research' was reported to the affected vendor on: 2025-10-06, 62 days ago. The vendor is given until 2026-02-03 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28222: Trend Micro 10.3.2025

A CVSS score 5.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N">AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N</a> severity vulnerability discovered by 'Xavier DANEST - Decathlon' was reported to the affected vendor on: 2025-10-03, 65 days ago. The vendor is given until 2026-01-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28202: Quest 10.3.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by ' Bobby Gould (@bobbygould5) of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-10-03, 65 days ago. The vendor is given until 2026-01-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27556: BusyBox 10.3.2025

A CVSS score 6.1 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L">AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L</a> severity vulnerability discovered by 'Ryota Shiga (GMO Flatt Security Inc.) with takumi-san.ai' was reported to the affected vendor on: 2025-10-03, 65 days ago. The vendor is given until 2026-01-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28221: EmbedThis 10.3.2025

A CVSS score 5.0 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L">AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L</a> severity vulnerability discovered by 'Tyler Zars' was reported to the affected vendor on: 2025-10-03, 65 days ago. The vendor is given until 2026-01-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27329: EmbedThis 10.3.2025

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Tyler Zars' was reported to the affected vendor on: 2025-10-03, 65 days ago. The vendor is given until 2026-01-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28122: Trend Micro 10.3.2025

A CVSS score 7.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Xavier DANEST - Decathlon' was reported to the affected vendor on: 2025-10-03, 65 days ago. The vendor is given until 2026-01-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27394: IceWarp 9.26.2025

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Oscar Bataille' was reported to the affected vendor on: 2025-09-26, 72 days ago. The vendor is given until 2026-01-24 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28045: Oracle 9.25.2025

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a> severity vulnerability discovered by 'Xiaobye(@xiaobye_tw) of DEVCORE Research Team' was reported to the affected vendor on: 2025-09-25, 73 days ago. The vendor is given until 2026-01-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27938: Oracle 9.25.2025

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a> severity vulnerability discovered by 'NiNi (@terrynini38514) from DEVCORE Research Team' was reported to the affected vendor on: 2025-09-25, 73 days ago. The vendor is given until 2026-01-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27925: Oracle 9.25.2025

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a> severity vulnerability discovered by 'VMBreakers(GANGMIN KIM, SANGBIN KIM, Un3xploitable)' was reported to the affected vendor on: 2025-09-25, 73 days ago. The vendor is given until 2026-01-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28129: Sante 9.25.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-09-25, 73 days ago. The vendor is given until 2026-01-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27870: Oracle 9.25.2025

A CVSS score 8.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H">AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</a> severity vulnerability discovered by 'VMBreakers(GANGMIN KIM, SANGBIN KIM, Un3xploitable)' was reported to the affected vendor on: 2025-09-25, 73 days ago. The vendor is given until 2026-01-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27923: Oracle 9.25.2025

A CVSS score 8.2 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H">AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</a> severity vulnerability discovered by 'VMBreakers(GANGMIN KIM, SANGBIN KIM, Un3xploitable)' was reported to the affected vendor on: 2025-09-25, 73 days ago. The vendor is given until 2026-01-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27353: Fuji Electric 9.25.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2025-09-25, 73 days ago. The vendor is given until 2026-01-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27989: NVIDIA 9.24.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Michael DePlante (@izobashi) of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-09-24, 74 days ago. The vendor is given until 2026-01-22 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28096: Lightning AI 9.24.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Michael DePlante (@izobashi) of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-09-24, 74 days ago. The vendor is given until 2026-01-22 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27632: Quest 9.24.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by '06fe5fd2bc53027c4a3b7e395af0b850e7b8a044' was reported to the affected vendor on: 2025-09-24, 74 days ago. The vendor is given until 2026-01-22 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27630: Quest 9.24.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by '06fe5fd2bc53027c4a3b7e395af0b850e7b8a044' was reported to the affected vendor on: 2025-09-24, 74 days ago. The vendor is given until 2026-01-22 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27626: Quest 9.24.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by '06fe5fd2bc53027c4a3b7e395af0b850e7b8a044' was reported to the affected vendor on: 2025-09-24, 74 days ago. The vendor is given until 2026-01-22 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27809: Quest 9.24.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by '06fe5fd2bc53027c4a3b7e395af0b850e7b8a044' was reported to the affected vendor on: 2025-09-24, 74 days ago. The vendor is given until 2026-01-22 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27648: Quest 9.24.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by '06fe5fd2bc53027c4a3b7e395af0b850e7b8a044' was reported to the affected vendor on: 2025-09-24, 74 days ago. The vendor is given until 2026-01-22 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27666: Quest 9.24.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by '06fe5fd2bc53027c4a3b7e395af0b850e7b8a044' was reported to the affected vendor on: 2025-09-24, 74 days ago. The vendor is given until 2026-01-22 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27631: Quest 9.24.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by '06fe5fd2bc53027c4a3b7e395af0b850e7b8a044' was reported to the affected vendor on: 2025-09-24, 74 days ago. The vendor is given until 2026-01-22 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27633: Quest 9.24.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by '06fe5fd2bc53027c4a3b7e395af0b850e7b8a044' was reported to the affected vendor on: 2025-09-24, 74 days ago. The vendor is given until 2026-01-22 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27625: Quest 9.24.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by '06fe5fd2bc53027c4a3b7e395af0b850e7b8a044' was reported to the affected vendor on: 2025-09-24, 74 days ago. The vendor is given until 2026-01-22 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28179: Autodesk 9.23.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Mat Powell of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-09-23, 75 days ago. The vendor is given until 2026-01-21 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28180: Autodesk 9.23.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Mat Powell of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-09-23, 75 days ago. The vendor is given until 2026-01-21 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28181: Autodesk 9.23.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Mat Powell of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-09-23, 75 days ago. The vendor is given until 2026-01-21 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27910: mcp-server-siri-shortcuts 9.23.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Peter Girnus (@gothburz) and Brandon Niemczyk of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-09-23, 75 days ago. The vendor is given until 2026-01-21 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28107: Siemens 9.19.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Michael DePlante (@izobashi) of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-09-19, 79 days ago. The vendor is given until 2026-01-17 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28116: Ivanti 9.19.2025

A CVSS score 7.1 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H">AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by '06fe5fd2bc53027c4a3b7e395af0b850e7b8a044' was reported to the affected vendor on: 2025-09-19, 79 days ago. The vendor is given until 2026-01-17 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28108: Siemens 9.19.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Michael DePlante (@izobashi) of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-09-19, 79 days ago. The vendor is given until 2026-01-17 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28121: Foundation Agents 9.19.2025

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Peter Girnus (@gothburz), Brandon Niemczyk of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-09-19, 79 days ago. The vendor is given until 2026-01-17 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28124: Foundation Agents 9.19.2025

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Peter Girnus (@gothburz) and Brandon Niemczyk of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-09-19, 79 days ago. The vendor is given until 2026-01-17 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-26897: Ivanti 9.19.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by '06fe5fd2bc53027c4a3b7e395af0b850e7b8a044' was reported to the affected vendor on: 2025-09-19, 79 days ago. The vendor is given until 2026-01-17 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-26889: NVIDIA 9.19.2025

A CVSS score 7.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a> severity vulnerability discovered by 'Tyler Zars and Rob Blakely of the Technical Debt Collectors' was reported to the affected vendor on: 2025-09-19, 79 days ago. The vendor is given until 2026-01-17 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27833: Anritsu 9.19.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'kimiya' was reported to the affected vendor on: 2025-09-19, 79 days ago. The vendor is given until 2026-01-17 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28148: Trend Micro 9.17.2025

A CVSS score 9.9 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H">AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a> severity vulnerability discovered by 'Hugo LECLERCQ' was reported to the affected vendor on: 2025-09-17, 81 days ago. The vendor is given until 2026-01-15 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27788: PDF-XChange 9.16.2025

A CVSS score 7.3 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Kolja Grassmann (Neodyme AG)' was reported to the affected vendor on: 2025-09-16, 82 days ago. The vendor is given until 2026-01-14 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28128: Autodesk 9.16.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Mat Powell of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-09-16, 82 days ago. The vendor is given until 2026-01-14 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28120: Autodesk 9.16.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Mat Powell of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-09-16, 82 days ago. The vendor is given until 2026-01-14 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28127: Autodesk 9.16.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Mat Powell of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-09-16, 82 days ago. The vendor is given until 2026-01-14 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28126: Autodesk 9.16.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Mat Powell of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-09-16, 82 days ago. The vendor is given until 2026-01-14 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-26000: CyberArk 9.12.2025

A CVSS score 7.0 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Nikolett Sipos & Nabeel Ahmed from NTT Belgium' was reported to the affected vendor on: 2025-09-12, 86 days ago. The vendor is given until 2026-01-10 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27909: RustDesk 9.11.2025

A CVSS score 5.5 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</a> severity vulnerability discovered by 'mad31k' was reported to the affected vendor on: 2025-09-11, 87 days ago. The vendor is given until 2026-01-09 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28102: Super Magic 9.11.2025

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Peter Girnus (@gothburz) and Brandon Niemczyk of Trend Zero Day Initiative ' was reported to the affected vendor on: 2025-09-11, 87 days ago. The vendor is given until 2026-01-09 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27670: Fuji Electric 9.11.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by '김명규' was reported to the affected vendor on: 2025-09-11, 87 days ago. The vendor is given until 2026-01-09 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27982: Trend Micro 9.11.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Lays (@_L4ys) of TRAPA Security' was reported to the affected vendor on: 2025-09-11, 87 days ago. The vendor is given until 2026-01-09 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28002: Trend Micro 9.11.2025

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Jacky Hsieh and Charles Yang @ CoreCloud Tech.' was reported to the affected vendor on: 2025-09-11, 87 days ago. The vendor is given until 2026-01-09 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27641: AzeoTech 9.11.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2025-09-11, 87 days ago. The vendor is given until 2026-01-09 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27523: AzeoTech 9.11.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2025-09-11, 87 days ago. The vendor is given until 2026-01-09 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28001: Trend Micro 9.11.2025

A CVSS score 9.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Jacky Hsieh and Charles Yang @ CoreCloud Tech.' was reported to the affected vendor on: 2025-09-11, 87 days ago. The vendor is given until 2026-01-09 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27811: AzeoTech 9.11.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2025-09-11, 87 days ago. The vendor is given until 2026-01-09 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-28038: Apple 9.10.2025

A CVSS score 8.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Hossein Lotfi (@hosselot) of Trend Zero Day Initiative' was reported to the affected vendor on: 2025-09-10, 88 days ago. The vendor is given until 2026-01-08 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

ZDI-CAN-27358: Fuji Electric 9.10.2025

A CVSS score 7.8 <a href="https://nvd.nist.gov/cvss.cfm?calculator&version=3.0&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a> severity vulnerability discovered by 'Rocco Calvi (@TecR0c) with TecSecurity' was reported to the affected vendor on: 2025-09-10, 88 days ago. The vendor is given until 2026-01-08 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.


© 1997-2025 hackerzinc
All rights reserved.