Количество 386 296
Количество 386 296
CVE-2026-58650
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-5864
Heap buffer overflow in WebAudio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
CVE-2026-58647
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.
CVE-2026-58644
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-58643
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-58641
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2026-58640
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-5863
Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-58639
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-58638
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
CVE-2026-58637
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
CVE-2026-58636
Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-58635
Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
CVE-2026-58634
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-58633
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-58632
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-58631
Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
CVE-2026-58630
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-5862
Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-58629
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-58650 Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | CVSS3: 7.8 | 0% Низкий | 25 дней назад | |
CVE-2026-5864 Heap buffer overflow in WebAudio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | CVSS3: 4.3 | 0% Низкий | 5 месяцев назад | |
CVE-2026-58647 Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network. | CVSS3: 8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-58644 Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CVSS3: 9.8 | 16% Средний | около 2 месяцев назад | |
CVE-2026-58643 Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network. | CVSS3: 6.1 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-58641 Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 25 дней назад | |
CVE-2026-58640 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | CVSS3: 7.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-5863 Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад | |
CVE-2026-58639 Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | CVSS3: 6.5 | 1% Низкий | 25 дней назад | |
CVE-2026-58638 Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. | CVSS3: 6 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-58637 Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-58636 Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-58635 Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-58634 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-58633 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-58632 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-58631 Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-58630 Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. | CVSS3: 10 | 0% Низкий | около 1 месяца назад | |
CVE-2026-5862 Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад | |
CVE-2026-58629 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу