Vulnerability Alerts

Vulnerability Alerts

CVEs, zero-days, exploits, and security advisories

VULNhighZero Day Initiative3 months ago

ZDI-26-133: (Pwn2Own) Music Assistant _update_library_item External Control of File Path Remote Code Execution Vulnerability

VULNhighZero Day Initiative3 months ago

ZDI-26-144: Trend Micro Apex Central Hub Server Server-Side Request Forgery Vulnerability

VULNhighZero Day Initiative3 months ago

ZDI-26-148: Trend Micro Apex Central Improper Authentication Privilege Escalation Vulnerability

VULNhighZero Day Initiative3 months ago

ZDI-26-149: Trend Micro Cleaner One Pro Link Following Denial-of-Service Vulnerability

VULNhighZero Day Initiative3 months ago

ZDI-26-139: Trend Micro Apex One Security Agent iCore Service Origin Validation Error Local Privilege Escalation Vulnerability

VULNhighZero Day Initiative3 months ago

ZDI-26-150: Docker Desktop for Mac Docker Model Runner Exposed Dangerous Function Denial-of-Service Vulnerability

VULNhighZero Day Initiative3 months ago

ZDI-26-146: Trend Micro Apex Central Manual Update Server-Side Request Forgery Vulnerability

VULNhighZero Day Initiative3 months ago

ZDI-26-141: Trend Micro Apex One Security Agent iCore Service Signature Verification Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability

VULNhighZero Day Initiative3 months ago

ZDI-26-145: Trend Micro Apex Central Scheduled Update Server-Side Request Forgery Vulnerability

VULNhighZero Day Initiative3 months ago

ZDI-26-134: Hewlett Packard Enterprise AutoPass License Server Authentication Bypass Vulnerability

VULNhighZero Day Initiative3 months ago

ZDI-26-142: Trend Micro Apex One Security Agent Cache Mechanism Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability

VULNhighZero Day Initiative3 months ago

ZDI-26-143: Trend Micro Apex One Security Agent TmSelfProtect Origin Validation Error Local Privilege Escalation Vulnerability

VULNhighZero Day Initiative3 months ago

ZDI-26-136: Trend Micro Apex One Console Directory Traversal Remote Code Execution Vulnerability

VULNhighZero Day Initiative3 months ago

ZDI-26-137: Trend Micro Apex One Console Directory Traversal Remote Code Execution Vulnerability

VULNGoogle Project Zero3 months ago

A Deep Dive into the GetProcessHandleFromHwnd API

VULNwatchTowr Labs4 months ago

Buy A Help Desk, Bundle A Remote Access Solution? (SolarWinds Web Help Desk Pre-Auth RCE Chain(s))

VULNMandiant4 months ago

Exposing the Undercurrent: Disrupting the GRIDTIDE Global Cyber Espionage Campaign

VULNhighZero Day Initiative4 months ago

ZDI-26-132: Siemens SINEC NMS Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

VULNcriticalMandiant4 months ago

From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day

VULNMandiant4 months ago

GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use

VULNGoogle Project Zero4 months ago

Bypassing Administrator Protection by Abusing UI Access

VULNMandiant4 months ago

Beyond the Battlefield: Threats to the Defense Industrial Base

VULNhighwatchTowr Labs4 months ago

Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340)

VULNhighGoogle Project Zero4 months ago

Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529

VULNGoogle Project Zero5 months ago

Bypassing Windows Administrator Protection

VULNwatchTowr Labs5 months ago

Attackers With Decompilers Strike Again (SmarterTools SmarterMail WT-2026-0001 Auth Bypass)

VULNhighGoogle Project Zero5 months ago

A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here?

VULNhighGoogle Project Zero5 months ago

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave

VULNhighGoogle Project Zero5 months ago

A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby

VULNhighwatchTowr Labs5 months ago

Do Smart People Ever Say They’re Smart? (SmarterTools SmarterMail Pre-Auth RCE CVE-2025-52691)