Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 382 285

Количество 382 285

nvd логотип

CVE-2026-58617

около 1 месяца назад

Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-58614

около 1 месяца назад

Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-58613

около 1 месяца назад

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-58612

16 дней назад

Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2026-58610

около 1 месяца назад

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-5860

5 месяцев назад

Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-58609

около 1 месяца назад

Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-58608

около 1 месяца назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-58602

около 1 месяца назад

Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-58601

около 1 месяца назад

Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-5859

5 месяцев назад

Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-58598

около 1 месяца назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-58597

около 2 месяцев назад

Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-58596

около 2 месяцев назад

Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2026-58595

около 1 месяца назад

Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-58594

около 1 месяца назад

Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-58593

около 2 месяцев назад

NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound middleware verifies the HTTP-signature actor and checks the origin of object.id, but never validates that attributedTo corresponds to the sender. In the object mock, attributedTo is used directly as a uid, and actors.assert silently ignores numeric identifiers (filtering them out without re-deriving the uid), so a federated remote actor can set attributedTo to a bare numeric value such as 1 and have the resulting post or private message created with that local uid as author, including the administrator account. This lets a remote attacker forge posts and direct messages attributed to arbitrary local users. Requires the ActivityPub/federation feature to be enabled.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-58592

около 2 месяцев назад

Ladybird contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaScript function is imported into a WebAssembly module via the ESM path, WebAssemblyModule.cpp passes a stack-local Wasm::FunctionType by reference to create_host_function, whose host callback captures and later reads that reference; once the ESM link-loop iteration ends the FunctionType is destroyed, leaving the callback with a dangling reference (the normal instantiate path uses a long-lived reference and is not affected). Stale result-type data lets the host callback return an empty result vector for a statically non-empty result, so the destination register retains an attacker-influenced value that is then consumed by the WASM-GC array.set handler, which bit-casts the reference low bits to an ArrayInstance pointer after only a null check, yielding an arbitrary write. A web page can chain this into code execution in the WebContent process. Verified reachable from HTM

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2026-58591

около 2 месяцев назад

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox versions: from 0.0.0 to 2.1.5, from 0.0.0 to 2.2.0.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-58590

около 2 месяцев назад

Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-58617

Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 8.1
1%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-58614

Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.

CVSS3: 5.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-58613

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-58612

Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.4
1%
Низкий
16 дней назад
nvd логотип
CVE-2026-58610

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-5860

Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-58609

Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-58608

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.

CVSS3: 8.8
1%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-58602

Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-58601

Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-5859

Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 8.8
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-58598

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-58597

Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 4.3
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-58596

Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 8.3
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-58595

Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 8.1
1%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-58594

Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
1%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-58593

NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound middleware verifies the HTTP-signature actor and checks the origin of object.id, but never validates that attributedTo corresponds to the sender. In the object mock, attributedTo is used directly as a uid, and actors.assert silently ignores numeric identifiers (filtering them out without re-deriving the uid), so a federated remote actor can set attributedTo to a bare numeric value such as 1 and have the resulting post or private message created with that local uid as author, including the administrator account. This lets a remote attacker forge posts and direct messages attributed to arbitrary local users. Requires the ActivityPub/federation feature to be enabled.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-58592

Ladybird contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaScript function is imported into a WebAssembly module via the ESM path, WebAssemblyModule.cpp passes a stack-local Wasm::FunctionType by reference to create_host_function, whose host callback captures and later reads that reference; once the ESM link-loop iteration ends the FunctionType is destroyed, leaving the callback with a dangling reference (the normal instantiate path uses a long-lived reference and is not affected). Stale result-type data lets the host callback return an empty result vector for a statically non-empty result, so the destination register retains an attacker-influenced value that is then consumed by the WASM-GC array.set handler, which bit-casts the reference low bits to an ArrayInstance pointer after only a null check, yielding an arbitrary write. A web page can chain this into code execution in the WebContent process. Verified reachable from HTM

CVSS3: 8.3
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-58591

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox versions: from 0.0.0 to 2.1.5, from 0.0.0 to 2.2.0.

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-58590

Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу