{"total":11,"items":[{"id":558,"title":"ZDI-26-713: GIMP APNG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability","original_title":"ZDI-26-713: GIMP APNG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability","source_rating":null,"summary":"This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…","ai":false,"actions":[],"url":"http://www.zerodayinitiative.com/advisories/ZDI-26-713/","type":"advisory","language":"en","published_at":"2026-09-16T05:00:00+00:00","severity":"laag","priority":0,"vendors":[],"cves":[{"id":"CVE-2026-92183","cvss":null,"epss":null,"epss_percentile":null,"in_kev":false,"kev_ransomware":false}],"cve_count":1,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"zdi","name":"Zero Day Initiative","category":"vulnerability","country":null,"license":"© Trend Micro Zero Day Initiative","reuse":"excerpt"},"bundle":null},{"id":566,"title":"ZDI-26-705: (0Day) BusyBox libarchive Symlink Directory Traversal Arbitrary File Creation Vulnerability","original_title":"ZDI-26-705: (0Day) BusyBox libarchive Symlink Directory Traversal Arbitrary File Creation Vulnerability","source_rating":null,"summary":"This vulnerability allows remote attackers to create arbitrary files on affected installations of BusyBox. User interaction is required to exploit this vulnerability in that the target must visit a…","ai":false,"actions":[],"url":"http://www.zerodayinitiative.com/advisories/ZDI-26-705/","type":"advisory","language":"en","published_at":"2026-09-16T05:00:00+00:00","severity":"laag","priority":0,"vendors":[],"cves":[{"id":"CVE-2026-92205","cvss":null,"epss":null,"epss_percentile":null,"in_kev":false,"kev_ransomware":false}],"cve_count":1,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"zdi","name":"Zero Day Initiative","category":"vulnerability","country":null,"license":"© Trend Micro Zero Day Initiative","reuse":"excerpt"},"bundle":null},{"id":568,"title":"ZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability","original_title":"ZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability","source_rating":null,"summary":"This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has…","ai":false,"actions":[],"url":"http://www.zerodayinitiative.com/advisories/ZDI-26-703/","type":"advisory","language":"en","published_at":"2026-09-16T05:00:00+00:00","severity":"laag","priority":0,"vendors":["Microsoft"],"cves":[{"id":"CVE-2026-92203","cvss":null,"epss":null,"epss_percentile":null,"in_kev":false,"kev_ransomware":false}],"cve_count":1,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"zdi","name":"Zero Day Initiative","category":"vulnerability","country":null,"license":"© Trend Micro Zero Day Initiative","reuse":"excerpt"},"bundle":null},{"id":559,"title":"ZDI-26-712: NoMachine nxhtd Server-Side Request Forgery Information Disclosure Vulnerability","original_title":"ZDI-26-712: NoMachine nxhtd Server-Side Request Forgery Information Disclosure Vulnerability","source_rating":null,"summary":"This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of NoMachine. Authentication is not required to exploit this vulnerability. The ZDI…","ai":false,"actions":[],"url":"http://www.zerodayinitiative.com/advisories/ZDI-26-712/","type":"advisory","language":"en","published_at":"2026-09-16T05:00:00+00:00","severity":"laag","priority":0,"vendors":[],"cves":[{"id":"CVE-2026-92210","cvss":null,"epss":null,"epss_percentile":null,"in_kev":false,"kev_ransomware":false}],"cve_count":1,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"zdi","name":"Zero Day Initiative","category":"vulnerability","country":null,"license":"© Trend Micro Zero Day Initiative","reuse":"excerpt"},"bundle":null},{"id":560,"title":"ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability","original_title":"ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability","source_rating":null,"summary":"This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system…","ai":false,"actions":[],"url":"http://www.zerodayinitiative.com/advisories/ZDI-26-711/","type":"advisory","language":"en","published_at":"2026-09-16T05:00:00+00:00","severity":"laag","priority":0,"vendors":["Redis"],"cves":[{"id":"CVE-2026-92209","cvss":null,"epss":null,"epss_percentile":null,"in_kev":false,"kev_ransomware":false}],"cve_count":1,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"zdi","name":"Zero Day Initiative","category":"vulnerability","country":null,"license":"© Trend Micro Zero Day Initiative","reuse":"excerpt"},"bundle":null},{"id":567,"title":"ZDI-26-704: (0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability","original_title":"ZDI-26-704: (0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability","source_rating":null,"summary":"This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has…","ai":false,"actions":[],"url":"http://www.zerodayinitiative.com/advisories/ZDI-26-704/","type":"advisory","language":"en","published_at":"2026-09-16T05:00:00+00:00","severity":"laag","priority":0,"vendors":[],"cves":[{"id":"CVE-2026-92204","cvss":null,"epss":null,"epss_percentile":null,"in_kev":false,"kev_ransomware":false}],"cve_count":1,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"zdi","name":"Zero Day Initiative","category":"vulnerability","country":null,"license":"© Trend Micro Zero Day Initiative","reuse":"excerpt"},"bundle":null},{"id":563,"title":"ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability","original_title":"ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability","source_rating":null,"summary":"This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the…","ai":false,"actions":[],"url":"http://www.zerodayinitiative.com/advisories/ZDI-26-708/","type":"advisory","language":"en","published_at":"2026-09-16T05:00:00+00:00","severity":"laag","priority":0,"vendors":["Microsoft"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"zdi","name":"Zero Day Initiative","category":"vulnerability","country":null,"license":"© Trend Micro Zero Day Initiative","reuse":"excerpt"},"bundle":null},{"id":564,"title":"ZDI-26-707: (0Day) MindsDB OpenBBtable Code Injection Remote Code Execution Vulnerability","original_title":"ZDI-26-707: (0Day) MindsDB OpenBBtable Code Injection Remote Code Execution Vulnerability","source_rating":null,"summary":"This vulnerability allows remote attackers to execute arbitrary code on affected installations of MindsDB. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS…","ai":false,"actions":[],"url":"http://www.zerodayinitiative.com/advisories/ZDI-26-707/","type":"advisory","language":"en","published_at":"2026-09-16T05:00:00+00:00","severity":"laag","priority":0,"vendors":[],"cves":[{"id":"CVE-2026-92207","cvss":null,"epss":null,"epss_percentile":null,"in_kev":false,"kev_ransomware":false}],"cve_count":1,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"zdi","name":"Zero Day Initiative","category":"vulnerability","country":null,"license":"© Trend Micro Zero Day Initiative","reuse":"excerpt"},"bundle":null},{"id":565,"title":"ZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerability","original_title":"ZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerability","source_rating":null,"summary":"This vulnerability allows remote attackers to execute arbitrary code on affected installations of CrewAI crewAI. User interaction is required to exploit this vulnerability in that the target must…","ai":false,"actions":[],"url":"http://www.zerodayinitiative.com/advisories/ZDI-26-706/","type":"advisory","language":"en","published_at":"2026-09-16T05:00:00+00:00","severity":"laag","priority":0,"vendors":[],"cves":[{"id":"CVE-2026-92206","cvss":null,"epss":null,"epss_percentile":null,"in_kev":false,"kev_ransomware":false}],"cve_count":1,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"zdi","name":"Zero Day Initiative","category":"vulnerability","country":null,"license":"© Trend Micro Zero Day Initiative","reuse":"excerpt"},"bundle":null},{"id":561,"title":"ZDI-26-710: NoMachine mDNS Heap-based Buffer Overflow Remote Code Execution Vulnerability","original_title":"ZDI-26-710: NoMachine mDNS Heap-based Buffer Overflow Remote Code Execution Vulnerability","source_rating":null,"summary":"This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NoMachine. Authentication is not required to exploit this vulnerability. The ZDI has…","ai":false,"actions":[],"url":"http://www.zerodayinitiative.com/advisories/ZDI-26-710/","type":"advisory","language":"en","published_at":"2026-09-16T05:00:00+00:00","severity":"laag","priority":0,"vendors":[],"cves":[{"id":"CVE-2026-92208","cvss":null,"epss":null,"epss_percentile":null,"in_kev":false,"kev_ransomware":false}],"cve_count":1,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"zdi","name":"Zero Day Initiative","category":"vulnerability","country":null,"license":"© Trend Micro Zero Day Initiative","reuse":"excerpt"},"bundle":null},{"id":562,"title":"ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability","original_title":"ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability","source_rating":null,"summary":"This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Secure Firewall Management Center. Authentication is not required to exploit this…","ai":false,"actions":[],"url":"http://www.zerodayinitiative.com/advisories/ZDI-26-709/","type":"advisory","language":"en","published_at":"2026-09-16T05:00:00+00:00","severity":"laag","priority":15,"vendors":["Cisco"],"cves":[{"id":"CVE-2026-20242","cvss":9.8,"epss":0.00639,"epss_percentile":0.48819,"in_kev":false,"kev_ransomware":false}],"cve_count":1,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":9.8,"epss_max":0.00639,"source_count":2,"ncsc":null,"source":{"slug":"zdi","name":"Zero Day Initiative","category":"vulnerability","country":null,"license":"© Trend Micro Zero Day Initiative","reuse":"excerpt"},"bundle":null}]}