ZDI-26-451: Docker Desktop for macOS Inference Server Permissive Allow List Sandbox Escape Vulnerability 24/07/2026
ZDI-26-450: AzeoTech DAQFactory CTL File Parsing Use-After-Free Remote Code Execution Vulnerability 24/07/2026
ZDI-26-449: AzeoTech DAQFactory CTL File Parsing Type Confusion Remote Code Execution Vulnerability 24/07/2026
ZDI-26-452: Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dify. User interaction is required to exploit... 24/07/2026 Zero-Day Initiative
ZDI-26-451: Docker Desktop for macOS Inference Server Permissive Allow List Sandbox Escape Vulnerability This vulnerability allows local attackers to escape the model runner sandbox on affected installations of Docker Desktop for macOS. An... 24/07/2026 Zero-Day Initiative
ZDI-26-450: AzeoTech DAQFactory CTL File Parsing Use-After-Free Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to... 24/07/2026 Zero-Day Initiative
ZDI-26-449: AzeoTech DAQFactory CTL File Parsing Type Confusion Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to... 24/07/2026 Zero-Day Initiative
ZDI-26-448: Bitdefender Total Security Shredder Link Following Local Privilege Escalation Vulnerability This vulnerability allows local attackers to escalate privileges on affected installations of Bitdefender Total Security. An attacker must first obtain... 24/07/2026 Zero-Day Initiative
ZDI-26-447: Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required... 24/07/2026 Zero-Day Initiative
Oracle Critical Patch Update, July 2026 Security Update Review Oracle released its third quarterly edition of this year’s Critical Patch Update. The update received patches for 1449 security vulnerabilities. Some of the... 22/07/2026 Qualys-Threat-Protect
ZDI-26-446: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the... 22/07/2026 Zero-Day Initiative
ZDI-26-445: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the... 22/07/2026 Zero-Day Initiative
WordPress wp2shell Vulnerabilities Exploited in the Wild (CVE-2026-63030 & CVE-2026-60137) Threat actors have released public exploit code for the WordPress core remote code execution vulnerabilities, named wp2shell. Tracked as CVE-2026-63030... 20/07/2026 Qualys-Threat-Protect