Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 384 790

Количество 384 790

nvd логотип

CVE-2026-58531

около 2 месяцев назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-58530

около 2 месяцев назад

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-5852

5 месяцев назад

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument igmpVer causes os command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2026-58529

около 2 месяцев назад

Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-58528

около 2 месяцев назад

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2026-58527

около 2 месяцев назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-58526

около 2 месяцев назад

Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-58525

около 2 месяцев назад

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2026-58524

2 месяца назад

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-58523

2 месяца назад

Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-58522

2 месяца назад

Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2026-58521

2 месяца назад

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection. This issue affects Mediawiki - Cargo Extension: from * before 1.43.9,1.44.6,1.45.4.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-58520

2 месяца назад

URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener Extension allows Cross-Site Flashing. This issue affects Mediawiki - UrlShortener Extension: from * before 1.43.9, 1.44.6, 1.45.4.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2026-5851

5 месяцев назад

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument enable results in os command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2026-58519

2 месяца назад

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS. This issue affects Mediawiki - Cargo Extension: from * before 3.9.1.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-58518

2 месяца назад

Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows Cross Site Request Forgery. This issue affects Mediawiki - RedirectManager Extension: from * before 1.3.3.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2026-58517

2 месяца назад

Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Authentication Bypass. This issue affects Mediawiki - WikiLambda Extension: from * before 1.43.9,1.44.6,1.45.4.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-58511

20 дней назад

Webhook Authorization Header Returned in Plaintext via API

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2026-58510

20 дней назад

GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-5850

5 месяцев назад

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument pptpPassThru leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-58531

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.

CVSS3: 7.5
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-58530

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-5852

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument igmpVer causes os command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

CVSS3: 9.8
14%
Средний
5 месяцев назад
nvd логотип
CVE-2026-58529

Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.

CVSS3: 7.1
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-58528

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

CVSS3: 6.8
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-58527

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-58526

Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-58525

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

CVSS3: 8.2
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-58524

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 5.4
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58523

Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.

CVSS3: 6.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58522

Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

CVSS3: 6.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58521

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection. This issue affects Mediawiki - Cargo Extension: from * before 1.43.9,1.44.6,1.45.4.

CVSS3: 9.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58520

URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener Extension allows Cross-Site Flashing. This issue affects Mediawiki - UrlShortener Extension: from * before 1.43.9, 1.44.6, 1.45.4.

CVSS3: 6.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5851

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument enable results in os command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

CVSS3: 9.8
14%
Средний
5 месяцев назад
nvd логотип
CVE-2026-58519

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS. This issue affects Mediawiki - Cargo Extension: from * before 3.9.1.

CVSS3: 5.4
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58518

Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows Cross Site Request Forgery. This issue affects Mediawiki - RedirectManager Extension: from * before 1.3.3.

CVSS3: 6.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58517

Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Authentication Bypass. This issue affects Mediawiki - WikiLambda Extension: from * before 1.43.9,1.44.6,1.45.4.

CVSS3: 4.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58511

Webhook Authorization Header Returned in Plaintext via API

CVSS3: 2.7
0%
Низкий
20 дней назад
nvd логотип
CVE-2026-58510

GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

CVSS3: 4.3
0%
Низкий
20 дней назад
nvd логотип
CVE-2026-5850

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument pptpPassThru leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

CVSS3: 9.8
16%
Средний
5 месяцев назад

Уязвимостей на страницу