Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 166

Количество 166

rocky логотип

RLSA-2026:35828

2 месяца назад

Important: grafana security update

EPSS: Низкий
rocky логотип

RLSA-2026:35827

2 месяца назад

Important: grafana security update

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2285-1

3 месяца назад

Security update for yq

EPSS: Низкий
rocky логотип

RLSA-2026:34359

2 месяца назад

Important: opentelemetry-collector security update

EPSS: Низкий
rocky логотип

RLSA-2026:34357

2 месяца назад

Important: opentelemetry-collector security update

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20892-1

3 месяца назад

Security update for yq

EPSS: Низкий
ubuntu логотип

CVE-2026-25681

4 месяца назад

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2026-25681

4 месяца назад

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-25681

4 месяца назад

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2026-25681

4 месяца назад

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2026-25681

4 месяца назад

Parsing arbitrary HTML which is then rendered using Render can result ...

CVSS3: 6.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3630-1

28 дней назад

Security update for kubevirt-1.6, virt-api-container-1.6, virt-controller-container-1.6, virt-exportproxy-container-1.6, virt-exportserver-container-1.6, virt-handler-container-1.6, virt-launcher-container-1.6, virt-libguestfs-tools-container-1.6, virt-operator-container-1.6, virt-pr-helper-container-1.6, virt-synchronization-controller-container-1.6

EPSS: Низкий
ubuntu логотип

CVE-2026-39821

4 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 9.6
EPSS: Низкий
redhat логотип

CVE-2026-39821

4 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2026-39821

4 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 9.6
EPSS: Низкий
msrc логотип

CVE-2026-39821

4 месяца назад

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

CVSS3: 10
EPSS: Низкий
debian логотип

CVE-2026-39821

4 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encode ...

CVSS3: 9.6
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21120-1

3 месяца назад

Security update for mcphost

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20956-1

3 месяца назад

Security update for trivy

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3203-1

около 2 месяцев назад

Security update for kubevirt

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:35828

Important: grafana security update

2 месяца назад
rocky логотип
RLSA-2026:35827

Important: grafana security update

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2285-1

Security update for yq

3 месяца назад
rocky логотип
RLSA-2026:34359

Important: opentelemetry-collector security update

2 месяца назад
rocky логотип
RLSA-2026:34357

Important: opentelemetry-collector security update

2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20892-1

Security update for yq

3 месяца назад
ubuntu логотип
CVE-2026-25681

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

CVSS3: 6.1
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-25681

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

CVSS3: 8.1
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-25681

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

CVSS3: 6.1
0%
Низкий
4 месяца назад
msrc логотип
CVE-2026-25681

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

CVSS3: 6.1
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-25681

Parsing arbitrary HTML which is then rendered using Render can result ...

CVSS3: 6.1
0%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3630-1

Security update for kubevirt-1.6, virt-api-container-1.6, virt-controller-container-1.6, virt-exportproxy-container-1.6, virt-exportserver-container-1.6, virt-handler-container-1.6, virt-launcher-container-1.6, virt-libguestfs-tools-container-1.6, virt-operator-container-1.6, virt-pr-helper-container-1.6, virt-synchronization-controller-container-1.6

28 дней назад
ubuntu логотип
CVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 9.6
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 8.2
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 9.6
1%
Низкий
4 месяца назад
msrc логотип
CVE-2026-39821

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

CVSS3: 10
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encode ...

CVSS3: 9.6
1%
Низкий
4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21120-1

Security update for mcphost

3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20956-1

Security update for trivy

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3203-1

Security update for kubevirt

около 2 месяцев назад

Уязвимостей на страницу