ZDI-26-489: (Pwn2Own) Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not... 30/07/2026 Zero-Day Initiative
ZDI-26-488: (Pwn2Own) Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not... 30/07/2026 Zero-Day Initiative
ZDI-26-487: (Pwn2Own) Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability This vulnerability allows local attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain... 30/07/2026 Zero-Day Initiative
Adobe Releases Patches for Multiple Critical Vulnerabilities Adobe released two security advisories addressing nine vulnerabilities affecting the Adobe Bridge and Adobe Format Plugins. All these vulnerabilities have critical severity ratings given by Adobe. Adobe Bridge... 29/07/2026 Qualys-Threat-Protect
ZDI-26-452: Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dify. User interaction is required to exploit... 24/07/2026 Zero-Day Initiative
ZDI-26-451: Docker Desktop for macOS Inference Server Permissive Allow List Sandbox Escape Vulnerability This vulnerability allows local attackers to escape the model runner sandbox on affected installations of Docker Desktop for macOS. An... 24/07/2026 Zero-Day Initiative
ZDI-26-450: AzeoTech DAQFactory CTL File Parsing Use-After-Free Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to... 24/07/2026 Zero-Day Initiative
ZDI-26-449: AzeoTech DAQFactory CTL File Parsing Type Confusion Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to... 24/07/2026 Zero-Day Initiative
ZDI-26-448: Bitdefender Total Security Shredder Link Following Local Privilege Escalation Vulnerability This vulnerability allows local attackers to escalate privileges on affected installations of Bitdefender Total Security. An attacker must first obtain... 24/07/2026 Zero-Day Initiative
ZDI-26-447: Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required... 24/07/2026 Zero-Day Initiative