Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 386 296

Количество 386 296

nvd логотип

CVE-2026-57993

2 месяца назад

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2026-57992

2 месяца назад

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-57991

2 месяца назад

Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2026-57990

около 1 месяца назад

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2026-5798

4 месяца назад

Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ endpoint, through manipulation of the ‘employeeID’ parameter. An authenticated attacker could exploit this vulnerability to access information about any employee (first names, last names, roles, job titles, and vacation records, among others) by modifying that identifier in requests sent to the server.

EPSS: Низкий
nvd логотип

CVE-2026-57989

около 1 месяца назад

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2026-57988

2 месяца назад

Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57987

2 месяца назад

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57986

2 месяца назад

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-57985

2 месяца назад

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2026-57984

2 месяца назад

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-57983

2 месяца назад

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2026-57982

около 2 месяцев назад

Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57981

2 месяца назад

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-57980

около 2 месяцев назад

Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-5797

5 месяцев назад

The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to insufficient input sanitization and the execution of do_shortcode() on user-submitted quiz answer text. User-submitted answers pass through sanitize_text_field() and htmlspecialchars(), which only strip HTML tags but do not encode or remove shortcode brackets [ and ]. When quiz results are displayed, the plugin calls do_shortcode() on the entire results page output (including user answers), causing any injected shortcodes to be executed. This makes it possible for unauthenticated attackers to inject arbitrary WordPress shortcodes such as [qsm_result id=X] to access other users' quiz submissions without authorization, as the qsm_result shortcode lacks any authorization checks.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-57979

около 2 месяцев назад

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57978

около 1 месяца назад

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-57977

2 месяца назад

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57976

около 2 месяцев назад

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-57993

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 7.4
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57992

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 7.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57991

Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.4
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57990

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.4
1%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-5798

Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ endpoint, through manipulation of the ‘employeeID’ parameter. An authenticated attacker could exploit this vulnerability to access information about any employee (first names, last names, roles, job titles, and vacation records, among others) by modifying that identifier in requests sent to the server.

0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-57989

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.4
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-57988

Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 7.1
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57987

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 6.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57986

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 7.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57985

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 7.6
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57984

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 7.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57983

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

CVSS3: 8.7
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57982

Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.

CVSS3: 6.5
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57981

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57980

Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-5797

The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to insufficient input sanitization and the execution of do_shortcode() on user-submitted quiz answer text. User-submitted answers pass through sanitize_text_field() and htmlspecialchars(), which only strip HTML tags but do not encode or remove shortcode brackets [ and ]. When quiz results are displayed, the plugin calls do_shortcode() on the entire results page output (including user answers), causing any injected shortcodes to be executed. This makes it possible for unauthenticated attackers to inject arbitrary WordPress shortcodes such as [qsm_result id=X] to access other users' quiz submissions without authorization, as the qsm_result shortcode lacks any authorization checks.

CVSS3: 5.3
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-57979

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57978

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 5.4
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-57977

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 7.1
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57976

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

CVSS3: 6.5
1%
Низкий
около 2 месяцев назад

Уязвимостей на страницу