Количество 382 285
Количество 382 285
CVE-2026-5863
Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-58639
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-58638
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
CVE-2026-58637
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
CVE-2026-58636
Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-58635
Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
CVE-2026-58634
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-58633
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-58632
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-58631
Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
CVE-2026-58630
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-5862
Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-58629
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
CVE-2026-58628
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.
CVE-2026-58627
Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2026-58626
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
CVE-2026-58624
Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though its GitPgmCommandFactory a way to configure an Apache MINA SSHD server such that SSH clients can remotely execute git commands via the JGit library on git repositories stored on the server. This GitPgmCommandFactory allowed a user authenticated via SSH to run any JGit command available, including commands that could write files at arbitrary places such as git archive with the --output option. Affected are SSH servers implemented with Apache MINA SSHD and using the GitPgmCommandFactory. If the GitPgmCommandFactory is not configured on the server, the server is not affected. It is recommended to upgrade affected servers to Apache MINA SSHD 2.19.0 or 3.0.0-M5, which fix this issue. The issue is fixed by restricting the available commands to a small whitelist of uncritical commands (such as
CVE-2026-5861
Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-58619
Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
CVE-2026-58618
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-5863 Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад | |
CVE-2026-58639 Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | CVSS3: 6.5 | 1% Низкий | 16 дней назад | |
CVE-2026-58638 Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. | CVSS3: 6 | 0% Низкий | около 1 месяца назад | |
CVE-2026-58637 Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | около 1 месяца назад | |
CVE-2026-58636 Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-58635 Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-58634 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-58633 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-58632 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-58631 Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-58630 Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. | CVSS3: 10 | 0% Низкий | около 1 месяца назад | |
CVE-2026-5862 Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад | |
CVE-2026-58629 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | около 1 месяца назад | |
CVE-2026-58628 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-58627 Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | CVSS3: 7.5 | 1% Низкий | около 1 месяца назад | |
CVE-2026-58626 Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. | CVSS3: 8.8 | 1% Низкий | около 1 месяца назад | |
CVE-2026-58624 Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though its GitPgmCommandFactory a way to configure an Apache MINA SSHD server such that SSH clients can remotely execute git commands via the JGit library on git repositories stored on the server. This GitPgmCommandFactory allowed a user authenticated via SSH to run any JGit command available, including commands that could write files at arbitrary places such as git archive with the --output option. Affected are SSH servers implemented with Apache MINA SSHD and using the GitPgmCommandFactory. If the GitPgmCommandFactory is not configured on the server, the server is not affected. It is recommended to upgrade affected servers to Apache MINA SSHD 2.19.0 or 3.0.0-M5, which fix this issue. The issue is fixed by restricting the available commands to a small whitelist of uncritical commands (such as | CVSS3: 5.4 | 1% Низкий | около 1 месяца назад | |
CVE-2026-5861 Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад | |
CVE-2026-58619 Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | около 1 месяца назад | |
CVE-2026-58618 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу