Vulnerability index

Browse CVEs

137 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Radare2 HIGH 7.8
CVE-2026-14789

A vulnerability was detected in radareorg radare2 up to 6.1.6. Affected by this issue is some unknown functionality of the file libr/bin/format/mdmp/…

Fix: after 6.1.6
Fix from $1,950 2026-07-06
Radare2 HIGH 7.8
CVE-2026-14787

A weakness has been identified in radareorg radare2 up to 6.1.6. Affected is the function cmd_print in the library libr/core/cmd_print.inc of the com…

Fix: after 6.1.6
Fix from $1,950 2026-07-06
Radare2 HIGH 7.8
CVE-2026-14788

A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the fi…

Fix: after 6.1.6
Fix from $1,950 2026-07-06
Radare2 MEDIUM 5.5
CVE-2026-14786

A security flaw has been discovered in radareorg radare2 up to 6.1.6. This impacts the function r_str_word_get0set of the file libr/util/str.c. The m…

Fix: 6.1.8+
Fix from $1,600 2026-07-06
Radare2 HIGH 7.8
CVE-2026-14759

A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function r_bin_java_inner_classes_attr_calc_size of the …

Fix: 6.1.8+
Fix from $1,950 2026-07-05
Radare2 HIGH 7.8
CVE-2026-14760

A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the…

Fix: 6.1.8+
Fix from $1,950 2026-07-05
Radare2 MEDIUM 5.5
CVE-2026-14761

A security vulnerability has been detected in radareorg radare2 up to 6.1.6. The affected element is the function r_str_ndup/r_str_append of the file…

Fix: 6.1.8+
Fix from $1,600 2026-07-05
Radare2 HIGH 7.8
CVE-2026-14757

A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This m…

Fix: 6.1.8+
Fix from $1,950 2026-07-05
Radare2 MEDIUM 5.5
CVE-2026-14758

A vulnerability was identified in radareorg radare2 up to 6.1.6. This vulnerability affects the function cmd_anal_opcode of the file libr/core/cmd_an…

Fix: 6.1.8+
Fix from $1,600 2026-07-05
Radare2 CRITICAL 9.8
CVE-2026-8696

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cau…

Fix: after 6.1.4
Fix from $2,300 2026-05-15
Radare2 CRITICAL 9.8
CVE-2026-8695

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption b…

Fix: after 6.1.4
Fix from $2,300 2026-05-15
Radare2 Mcp Server HIGH 8.8
CVE-2026-6942

radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by by…

Fix: 1.7.0+
Fix from $1,950 2026-04-23
Radare2 HIGH 7.8
CVE-2026-6941

radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the…

Fix: 6.1.4+
Fix from $1,950 2026-04-23
Radare2 HIGH 7.1
CVE-2026-6940

radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively delete arbitrary direct…

Fix: 6.1.4+
Fix from $1,950 2026-04-23
Radare2 HIGH 7.8
CVE-2026-40517

radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitra…

Fix: 6.1.4+
Fix from $1,950 2026-04-22
Radare2 HIGH 7.8
CVE-2026-40527

radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malici…

Fix: 6.1.6+
Fix from $1,950 2026-04-17
Radare2 HIGH 7.8
CVE-2026-40499

radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute…

Fix: after 6.1.4
Fix from $1,950 2026-04-15
Radare2 MEDIUM 5.5
CVE-2025-63745

A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the info() function of bin_ne.c. A crafted binary input c…

Fix: after 6.0.5
Fix from $1,600 2025-11-14
Radare2 MEDIUM 5.5
CVE-2025-60360

radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init.

Fix: after 5.9.8
Fix from $1,600 2025-10-17
Radare2 MEDIUM 5.5
CVE-2025-60359

radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new.

Fix: after 5.9.8
Fix from $1,600 2025-10-17
Radare2 MEDIUM 5.5
CVE-2025-60358

radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.

Fix: after 5.9.8
Fix from $1,600 2025-10-16
Radare2 CRITICAL 9.8
CVE-2025-1864

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in radareorg radare2 allows Overflow Buffers.This issue affects…

Fix: after 5.9.8
Fix from $2,300 2025-03-03
Radare2 CRITICAL 9.8
CVE-2025-1744

Out-of-bounds Write vulnerability in radareorg radare2 allows heap-based buffer over-read or buffer overflow.This issue affects radare2: before <5.…

Fix: after 5.9.8
Fix from $2,300 2025-02-28
Radare2 CRITICAL 9.8
CVE-2024-29646

Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the name, type, or group fields.

Patch available
Fix from $2,300 2024-12-17
Radare2 HIGH 7.8
CVE-2024-11858

A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Applicatio…

Fix: after 5.9.8
Fix from $1,950 2024-12-15
Radare2 HIGH 7.8
CVE-2024-29645

Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the parse_die function.

Patch available
Fix from $1,950 2024-12-02
Radare2 MEDIUM 5.5
CVE-2024-48241

An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.

Fix: after 5.9.4
Fix from $1,600 2024-10-30
Radare2 MEDIUM 5.5
CVE-2024-26475

An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the grub_sfs_read…

Fix: 5.8.8+
Fix from $1,600 2024-03-14
Radare2 HIGH 7.5
CVE-2023-47016

radare2 5.8.9 has an out-of-bounds read in r_bin_object_set_items in libr/bin/bobj.c, causing a crash in r_read_le32 in libr/include/r_endian.h.

Fix: 5.9.0+
Fix from $1,950 2023-11-22
Radare2 CRITICAL 9.8
CVE-2023-46569

An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-dis.h.

Fix: 5.9.0+
Fix from $2,300 2023-10-28