Vulnerabilities
Vulnerable Software
Security Vulnerabilities
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field pointer could be lower than the field-metadata section base, making subtraction produce a negative logical index. The vulnerability is triggered by parsing Swift type and class metadata from a crafted Mach-O file. The derived index was used to read four bytes immediately before the allocated field-metadata buffer. This can cause incorrect metadata processing or process termination; no attacker-observable memory disclosure has been demonstrated. This issue is fixed in version 6.2.0.
CVSS Score
3.3
EPSS Score
0.001
Published
2026-09-22
CVE-2026-94127
Known exploited
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS Score
9.3
EPSS Score
0.022
Published
2026-09-22
NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
CVSS Score
7.8
EPSS Score
0.002
Published
2026-09-22
NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
CVSS Score
7.8
EPSS Score
0.004
Published
2026-09-22
NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
CVSS Score
7.8
EPSS Score
0.004
Published
2026-09-22
CVE-2026-93616
Known exploited
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
CVSS Score
9.8
EPSS Score
0.197
Published
2026-09-22
Privilege escalation due to weak configuration during package extraction process.
CVSS Score
8.8
EPSS Score
0.001
Published
2026-09-22
Privilege escalation due to weak configuration while temporary file handling.
CVSS Score
8.8
EPSS Score
0.001
Published
2026-09-22
Improper authorization leads to Remote Code Execution via SocketIO interface.
CVSS Score
9.8
EPSS Score
0.003
Published
2026-09-22
CVE-2026-93952
Known exploited
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.
CVSS Score
9.5
EPSS Score
0.009
Published
2026-09-22


Contact Us

Shodan ® - All rights reserved