Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 386 939

Количество 386 939

nvd логотип

CVE-2026-57623

2 месяца назад

Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.

CVSS3: 9
EPSS: Низкий
nvd логотип

CVE-2026-57622

2 месяца назад

Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-57621

2 месяца назад

Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-57620

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.8.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57619

2 месяца назад

Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57618

2 месяца назад

Contributor Cross Site Scripting (XSS) in Neve PRO <= 3.1.2 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57617

2 месяца назад

Contributor Cross Site Scripting (XSS) in SeedProd Pro < 6.19.5 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-5760

5 месяцев назад

SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment().

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-57600

около 2 месяцев назад

Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-57599

около 2 месяцев назад

There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH.

CVSS3: 6.6
EPSS: Низкий
nvd логотип

CVE-2026-5758

5 месяцев назад

JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker may alter the application logic, bypass security checks, cause a DoS or achieve remote code execution.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57589

2 месяца назад

sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-after-free after tsleep in sys_semget().

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2026-57588

2 месяца назад

A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data.

CVSS3: 3.3
EPSS: Низкий
nvd логотип

CVE-2026-57587

2 месяца назад

A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-57585

2 месяца назад

MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-57584

около 2 месяцев назад

Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application built with a default router registers a built-in route whose compiled PCRE pattern contains the nested quantifier (/.), and the same construct is produced by the /:params placeholder and the CLI router. Phalcon\Mvc\Router::handle() matches this pattern against the attacker-controlled request URI on every request, so a crafted path such as one containing repeated slashes followed by decoded newlines can trigger catastrophic backtracking and cause CPU exhaustion or route-matching failure. This issue is fixed in version 5.15.0.

EPSS: Низкий
nvd логотип

CVE-2026-57580

20 дней назад

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK or EMAIL_LINK user-matching mode interprets an XML comment in a NameID differently from the identity provider's signed assertion. An attacker with an account on the source identity provider who can set the account's NameID can inject an XML comment that truncates the value used by authentik to the text before the comment while the signed assertion remains valid. A crafted NameID can therefore truncate to a victim's username or email and bind the attacker's external identity to the victim's existing account. This grants full takeover without the victim's password or the identity provider's private key, and the malicious link persists so later logins succeed without the comment. Sources using the default unique-identifier matching mode and authentik's outbound SAML Provider role are not affected. This issue is fixed in versions 2026.2.6 and 2

EPSS: Низкий
nvd логотип

CVE-2026-5757

2 месяца назад

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-57575

около 2 месяцев назад

Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a Server-Side Request Forgery (SSRF) vulnerability in URL preview functionality in UrlPreviewService. Due to missing network restrictions before establishing outbound connections, a remote attacker can cause the Misskey server to initiate HTTP requests to loopback, private, or link-local services. Because IP address validation takes place after the request has been sent and the process is subsequently rejected, no sensitive internal data is believed to be transmitted back or exposed to the attacker. This issue is fixed in version 2026.6.0.

EPSS: Низкий
nvd логотип

CVE-2026-57574

около 2 месяцев назад

Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a vulnerability in Time-based One-Time Password (TOTP) authentication in UserAuthService where insufficient validation of used tokens allows the reuse of a single-use code within its valid time step. If both credentials and a TOTP code are obtained concurrently, an attacker may reuse the code to perform unauthorized actions, potentially leading to account takeover. This issue is fixed in version 2026.6.0.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-57623

Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.

CVSS3: 9
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57622

Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.

CVSS3: 4.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57621

Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.

CVSS3: 9.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57620

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.8.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57619

Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57618

Contributor Cross Site Scripting (XSS) in Neve PRO <= 3.1.2 versions.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57617

Contributor Cross Site Scripting (XSS) in SeedProd Pro < 6.19.5 versions.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5760

SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment().

CVSS3: 9.8
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-57600

Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57599

There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH.

CVSS3: 6.6
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-5758

JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker may alter the application logic, bypass security checks, cause a DoS or achieve remote code execution.

CVSS3: 6.5
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-57589

sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-after-free after tsleep in sys_semget().

CVSS3: 7.4
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57588

A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data.

CVSS3: 3.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57587

A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data.

CVSS3: 5.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57585

MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.

CVSS3: 7.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57584

Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application built with a default router registers a built-in route whose compiled PCRE pattern contains the nested quantifier (/.), and the same construct is produced by the /:params placeholder and the CLI router. Phalcon\Mvc\Router::handle() matches this pattern against the attacker-controlled request URI on every request, so a crafted path such as one containing repeated slashes followed by decoded newlines can trigger catastrophic backtracking and cause CPU exhaustion or route-matching failure. This issue is fixed in version 5.15.0.

1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57580

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK or EMAIL_LINK user-matching mode interprets an XML comment in a NameID differently from the identity provider's signed assertion. An attacker with an account on the source identity provider who can set the account's NameID can inject an XML comment that truncates the value used by authentik to the text before the comment while the signed assertion remains valid. A crafted NameID can therefore truncate to a victim's username or email and bind the attacker's external identity to the victim's existing account. This grants full takeover without the victim's password or the identity provider's private key, and the malicious link persists so later logins succeed without the comment. Sources using the default unique-identifier matching mode and authentik's outbound SAML Provider role are not affected. This issue is fixed in versions 2026.2.6 and 2

0%
Низкий
20 дней назад
nvd логотип
CVE-2026-5757

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence.

CVSS3: 7.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57575

Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a Server-Side Request Forgery (SSRF) vulnerability in URL preview functionality in UrlPreviewService. Due to missing network restrictions before establishing outbound connections, a remote attacker can cause the Misskey server to initiate HTTP requests to loopback, private, or link-local services. Because IP address validation takes place after the request has been sent and the process is subsequently rejected, no sensitive internal data is believed to be transmitted back or exposed to the attacker. This issue is fixed in version 2026.6.0.

1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57574

Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a vulnerability in Time-based One-Time Password (TOTP) authentication in UserAuthService where insufficient validation of used tokens allows the reuse of a single-use code within its valid time step. If both credentials and a TOTP code are obtained concurrently, an attacker may reuse the code to perform unauthorized actions, potentially leading to account takeover. This issue is fixed in version 2026.6.0.

1%
Низкий
около 2 месяцев назад

Уязвимостей на страницу