Количество 385 613
Количество 385 613
CVE-2026-58536
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-58535
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-58534
Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
CVE-2026-58533
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-58532
Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-58531
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.
CVE-2026-58530
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
CVE-2026-5852
A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument igmpVer causes os command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
CVE-2026-58529
Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.
CVE-2026-58528
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-58527
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-58526
Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.
CVE-2026-58525
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-58524
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-58523
Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-58522
Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
CVE-2026-58521
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection. This issue affects Mediawiki - Cargo Extension: from * before 1.43.9,1.44.6,1.45.4.
CVE-2026-58520
URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener Extension allows Cross-Site Flashing. This issue affects Mediawiki - UrlShortener Extension: from * before 1.43.9, 1.44.6, 1.45.4.
CVE-2026-5851
A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument enable results in os command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
CVE-2026-58519
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS. This issue affects Mediawiki - Cargo Extension: from * before 3.9.1.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-58536 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-58535 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | CVSS3: 6.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-58534 Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. | CVSS3: 8.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-58533 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | CVSS3: 6.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-58532 Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-58531 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network. | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-58530 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-5852 A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument igmpVer causes os command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. | CVSS3: 9.8 | 14% Средний | 5 месяцев назад | |
CVE-2026-58529 Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network. | CVSS3: 7.1 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-58528 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. | CVSS3: 6.8 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-58527 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-58526 Use after free in Windows Storage allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-58525 Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | CVSS3: 8.2 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-58524 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | CVSS3: 5.4 | 0% Низкий | 2 месяца назад | |
CVE-2026-58523 Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network. | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-58522 Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. | CVSS3: 6.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-58521 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection. This issue affects Mediawiki - Cargo Extension: from * before 1.43.9,1.44.6,1.45.4. | CVSS3: 9.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-58520 URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener Extension allows Cross-Site Flashing. This issue affects Mediawiki - UrlShortener Extension: from * before 1.43.9, 1.44.6, 1.45.4. | CVSS3: 6.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-5851 A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument enable results in os command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. | CVSS3: 9.8 | 14% Средний | 5 месяцев назад | |
CVE-2026-58519 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS. This issue affects Mediawiki - Cargo Extension: from * before 3.9.1. | CVSS3: 5.4 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу