radare records
181 published records for vendor radare.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 28.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read47
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer25
- CWE-416 Use After Free19
- CWE-476 NULL Pointer Dereference18
- CWE-787 Out-of-bounds Write14
- CWE-122 Heap-based Buffer Overflow11
The weakness classes this vendor ships most often: where to look.
CWEAll records
181 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-24133No exploit | A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arradare · radare2-extras · CWE-787 | Critical9.8 | — | 2.6% | Jul 14, 2021 |
40Plan | CVE-2025-1744No exploit | Out-of-bounds Write in radare2radare · radare2 · CWE-787 | Critical10.0 | — | 0.5% | Feb 28, 2025 |
40Plan | CVE-2025-1864No exploit | Buffer Overflow and Potential Code Execution in Radare2radare · radare2 · CWE-119 | Critical10.0 | — | 0.5% | Mar 3, 2025 |
39Monitor | CVE-2022-0559No exploit | Use After Free in radareorg/radare2radare · radare2 · CWE-416 | Critical9.8 | — | 1.3% | Feb 16, 2022 |
39Monitor | CVE-2022-0139No exploit | Use After Free in radareorg/radare2radare · radare2 · CWE-416 | Critical9.8 | — | 1.2% | Feb 8, 2022 |
39Monitor | CVE-2023-4322No exploit | Heap-based Buffer Overflow in radareorg/radare2radare · radare2 · CWE-122 | Critical9.8 | — | 0.9% | Aug 14, 2023 |
39Monitor | CVE-2024-29646No exploit | Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the name, type, or group fields.radare · radare2 · CWE-120 | Critical9.8 | — | 0.9% | Dec 17, 2024 |
39Monitor | CVE-2023-46569No exploit | An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-dis.h.radare · radare2 · CWE-125 | Critical9.8 | — | 0.9% | Oct 27, 2023 |
39Monitor | CVE-2023-46570No exploit | An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32 function of libr/arch/p/nds32/nds32-dis.h.radare · radare2 · CWE-125 | Critical9.8 | — | 0.9% | Oct 27, 2023 |
38Monitor | CVE-2026-6942No exploit | radare2-mcp <=1.6.0 OS Command Injection via Shell Metacharacter Bypassradare · radare2 mcp server · CWE-78 | Critical9.3 | — | 3.0% | Apr 23, 2026 |
38Monitor | CVE-2020-15121No exploit | Command injection in Radare2radare · radare2 · CWE-78 | Critical9.6 | — | 1.6% | Jul 20, 2020 |
36Monitor | CVE-2022-1899No exploit | Out-of-bounds Read in radareorg/radare2radare · radare2 · CWE-125 | Critical9.1 | — | 1.5% | May 26, 2022 |
36Monitor | CVE-2020-27794No exploit | A double free issue was discovered in radare2 in cmd_info.c:cmd_info().radare · radare2 · CWE-415 | Critical9.1 | — | 1.1% | Aug 19, 2022 |
36Monitor | CVE-2022-1297No exploit | Out-of-bounds Read in r_bin_ne_get_entrypoints function in radareorg/radare2radare · radare2 · CWE-125 | Critical9.1 | — | 0.9% | Apr 11, 2022 |
36Monitor | CVE-2022-1296No exploit | Out-of-bounds read in `r_bin_ne_get_relocs` function in radareorg/radare2radare · radare2 · CWE-125 | Critical9.1 | — | 0.8% | Apr 11, 2022 |
36Monitor | CVE-2021-32495No exploit | Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function.radare · radare2 · CWE-416 | Critical9.1 | — | 0.8% | Jul 7, 2023 |
35Monitor | CVE-2023-5686No exploit | Heap-based Buffer Overflow in radareorg/radare2radare · radare2 · CWE-122 | High8.8 | — | 0.8% | Oct 20, 2023 |
34Monitor | CVE-2026-40517No exploit | radare2 < 6.1.4 Command Injection via PDB Parser Symbol Namesradare · radare2 · CWE-78 | High8.4 | — | 1.7% | Apr 22, 2026 |
34Monitor | CVE-2026-40499No exploit | radare2 < 6.1.4 Command Injection via PDB Parser print_gvars()radare · radare2 · CWE-78 | High8.4 | — | 1.7% | Apr 15, 2026 |
34Monitor | CVE-2026-40527No exploit | radare2 Command Injection via DWARF Parameter Namesradare · radare2 · CWE-78 | High8.5 | — | 1.5% | Apr 17, 2026 |
34Monitor | CVE-2026-8695No exploit | radare2 6.1.5 Use-After-Free via gdbr_threads_list()radare · radare2 · CWE-416 | High8.7 | — | 1.1% | May 15, 2026 |
34Monitor | CVE-2026-8696No exploit | radare2 6.1.5 Use-After-Free via gdbr_pids_list()radare · radare2 · CWE-416 | High8.7 | — | 1.0% | May 15, 2026 |
32Monitor | CVE-2019-14745Proof of concept | In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c.radare · radare2 · CWE-77 | High7.8 | — | 4.5% | Aug 7, 2019 |
32Monitor | CVE-2019-19590No exploit | In radare2 through 4.0, there is an integer overflow for the variable new_token_size in the function r_asm_massemble at libr/asm/asm.c.radare · radare2 · CWE-190 | High7.8 | — | 2.5% | Dec 4, 2019 |
32Monitor | CVE-2019-16718No exploit | In radare2 before 3.9.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c.radare · radare2 · CWE-78 | High7.8 | — | 2.3% | Sep 23, 2019 |
- CVE-2020-2413340Plan
A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute ar
CriticalCVSS 9.8No exploitEPSS 3%radare · radare2-extrasJul 14, 2021
- CVE-2025-174440Plan
Out-of-bounds Write in radare2
CriticalCVSS 10.0No exploitEPSS 1%radare · radare2Feb 28, 2025
- CVE-2025-186440Plan
Buffer Overflow and Potential Code Execution in Radare2
CriticalCVSS 10.0No exploitEPSS 0%radare · radare2Mar 3, 2025
- CVE-2022-055939Monitor
Use After Free in radareorg/radare2
CriticalCVSS 9.8No exploitEPSS 1%radare · radare2Feb 16, 2022
- CVE-2022-013939Monitor
Use After Free in radareorg/radare2
CriticalCVSS 9.8No exploitEPSS 1%radare · radare2Feb 8, 2022
- CVE-2023-432239Monitor
Heap-based Buffer Overflow in radareorg/radare2
CriticalCVSS 9.8No exploitEPSS 1%radare · radare2Aug 14, 2023
- CVE-2024-2964639Monitor
Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the name, type, or group fields.
CriticalCVSS 9.8No exploitEPSS 1%radare · radare2Dec 17, 2024
- CVE-2023-4656939Monitor
An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-dis.h.
CriticalCVSS 9.8No exploitEPSS 1%radare · radare2Oct 27, 2023
- CVE-2023-4657039Monitor
An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32 function of libr/arch/p/nds32/nds32-dis.h.
CriticalCVSS 9.8No exploitEPSS 1%radare · radare2Oct 27, 2023
- CVE-2026-694238Monitor
radare2-mcp <=1.6.0 OS Command Injection via Shell Metacharacter Bypass
CriticalCVSS 9.3No exploitEPSS 3%radare · radare2 mcp serverApr 23, 2026
- CVE-2020-1512138Monitor
Command injection in Radare2
CriticalCVSS 9.6No exploitEPSS 2%radare · radare2Jul 20, 2020
- CVE-2022-189936Monitor
Out-of-bounds Read in radareorg/radare2
CriticalCVSS 9.1No exploitEPSS 1%radare · radare2May 26, 2022
- CVE-2020-2779436Monitor
A double free issue was discovered in radare2 in cmd_info.c:cmd_info().
CriticalCVSS 9.1No exploitEPSS 1%radare · radare2Aug 19, 2022
- CVE-2022-129736Monitor
Out-of-bounds Read in r_bin_ne_get_entrypoints function in radareorg/radare2
CriticalCVSS 9.1No exploitEPSS 1%radare · radare2Apr 11, 2022
- CVE-2022-129636Monitor
Out-of-bounds read in `r_bin_ne_get_relocs` function in radareorg/radare2
CriticalCVSS 9.1No exploitEPSS 1%radare · radare2Apr 11, 2022
- CVE-2021-3249536Monitor
Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function.
CriticalCVSS 9.1No exploitEPSS 1%radare · radare2Jul 7, 2023
- CVE-2023-568635Monitor
Heap-based Buffer Overflow in radareorg/radare2
HighCVSS 8.8No exploitEPSS 1%radare · radare2Oct 20, 2023
- CVE-2026-4051734Monitor
radare2 < 6.1.4 Command Injection via PDB Parser Symbol Names
HighCVSS 8.4No exploitEPSS 2%radare · radare2Apr 22, 2026
- CVE-2026-4049934Monitor
radare2 < 6.1.4 Command Injection via PDB Parser print_gvars()
HighCVSS 8.4No exploitEPSS 2%radare · radare2Apr 15, 2026
- CVE-2026-4052734Monitor
radare2 Command Injection via DWARF Parameter Names
HighCVSS 8.5No exploitEPSS 1%radare · radare2Apr 17, 2026
- CVE-2026-869534Monitor
radare2 6.1.5 Use-After-Free via gdbr_threads_list()
HighCVSS 8.7No exploitEPSS 1%radare · radare2May 15, 2026
- CVE-2026-869634Monitor
radare2 6.1.5 Use-After-Free via gdbr_pids_list()
HighCVSS 8.7No exploitEPSS 1%radare · radare2May 15, 2026
- CVE-2019-1474532Monitor
In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c.
HighCVSS 7.8Proof of conceptEPSS 4%radare · radare2Aug 7, 2019
- CVE-2019-1959032Monitor
In radare2 through 4.0, there is an integer overflow for the variable new_token_size in the function r_asm_massemble at libr/asm/asm.c.
HighCVSS 7.8No exploitEPSS 3%radare · radare2Dec 4, 2019
- CVE-2019-1671832Monitor
In radare2 before 3.9.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c.
HighCVSS 7.8No exploitEPSS 2%radare · radare2Sep 23, 2019