Количество 25 045
Количество 25 045
CVE-2026-57083
Windows Media Photo Codec Information Disclosure Vulnerability
CVE-2026-57062
CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.
CVE-2026-56852
Infinite loop on invalid input in golang.org/x/text
CVE-2026-56650
Windows Network File System Elevation of Privilege Vulnerability
CVE-2026-56649
Windows Network File System Remote Code Execution Vulnerability
CVE-2026-56648
Windows NFS Server Elevation of Privilege Vulnerability
CVE-2026-56647
Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerability
CVE-2026-56646
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-56645
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-56644
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2026-56643
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2026-56642
Microsoft Fabric Data Warehouse Remote Code Execution Vulnerability
CVE-2026-56444
Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration
CVE-2026-56434
NGINX ngx_http_ssi_module vulnerability
CVE-2026-56416
Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name
CVE-2026-56412
libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.
CVE-2026-56411
xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
CVE-2026-56410
xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
CVE-2026-56409
xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
CVE-2026-56407
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-57083 Windows Media Photo Codec Information Disclosure Vulnerability | CVSS3: 5.5 | 0% Низкий | 19 дней назад | |
CVE-2026-57062 CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182. | CVSS3: 2.9 | 0% Низкий | около 1 месяца назад | |
CVE-2026-56852 Infinite loop on invalid input in golang.org/x/text | 0% Низкий | 9 дней назад | ||
CVE-2026-56650 Windows Network File System Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | 19 дней назад | |
CVE-2026-56649 Windows Network File System Remote Code Execution Vulnerability | CVSS3: 5.9 | 1% Низкий | 19 дней назад | |
CVE-2026-56648 Windows NFS Server Elevation of Privilege Vulnerability | CVSS3: 7.5 | 0% Низкий | 19 дней назад | |
CVE-2026-56647 Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerability | CVSS3: 8.8 | 1% Низкий | 19 дней назад | |
CVE-2026-56646 Microsoft Edge (Chromium-based) Spoofing Vulnerability | CVSS3: 6.5 | 1% Низкий | около 1 месяца назад | |
CVE-2026-56645 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | CVSS3: 8.8 | 1% Низкий | около 1 месяца назад | |
CVE-2026-56644 DirectX Graphics Kernel Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | 19 дней назад | |
CVE-2026-56643 DirectX Graphics Kernel Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | 19 дней назад | |
CVE-2026-56642 Microsoft Fabric Data Warehouse Remote Code Execution Vulnerability | CVSS3: 8.8 | 1% Низкий | 19 дней назад | |
CVE-2026-56444 Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration | CVSS3: 5.9 | 0% Низкий | 11 дней назад | |
CVE-2026-56434 NGINX ngx_http_ssi_module vulnerability | CVSS3: 6.5 | 0% Низкий | 15 дней назад | |
CVE-2026-56416 Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name | CVSS3: 4.8 | 0% Низкий | 11 дней назад | |
CVE-2026-56412 libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219. | CVSS3: 4.9 | 0% Низкий | около 1 месяца назад | |
CVE-2026-56411 xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations. | CVSS3: 6.9 | 0% Низкий | около 1 месяца назад | |
CVE-2026-56410 xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. | CVSS3: 6.9 | 0% Низкий | около 1 месяца назад | |
CVE-2026-56409 xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-56407 libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen. | CVSS3: 6.9 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу