Количество 331 614
Количество 331 614
CVE-2026-2082
A vulnerability was identified in D-Link DIR-823X 250416. The impacted element is an unknown function of the file /goform/set_mac_clone. Such manipulation of the argument mac leads to os command injection. The attack may be performed from remote. The exploit is publicly available and might be used.
CVE-2026-20829
Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.
CVE-2026-20828
Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-20827
Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally.
CVE-2026-20826
Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally.
CVE-2026-20825
Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.
CVE-2026-20824
Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-20823
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-20822
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2026-20821
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally.
CVE-2026-20820
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-2081
A vulnerability was determined in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_password. This manipulation of the argument http_passwd causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2026-20819
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.
CVE-2026-20818
Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally.
CVE-2026-20817
Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
CVE-2026-20816
Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-20815
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
CVE-2026-20814
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-20812
Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network.
CVE-2026-20811
Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-2082 A vulnerability was identified in D-Link DIR-823X 250416. The impacted element is an unknown function of the file /goform/set_mac_clone. Such manipulation of the argument mac leads to os command injection. The attack may be performed from remote. The exploit is publicly available and might be used. | CVSS3: 4.7 | 0% Низкий | 3 дня назад | |
CVE-2026-20829 Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 27 дней назад | |
CVE-2026-20828 Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack. | CVSS3: 4.6 | 0% Низкий | 27 дней назад | |
CVE-2026-20827 Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 27 дней назад | |
CVE-2026-20826 Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 27 дней назад | |
CVE-2026-20825 Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally. | CVSS3: 4.4 | 0% Низкий | 27 дней назад | |
CVE-2026-20824 Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally. | CVSS3: 5.5 | 0% Низкий | 27 дней назад | |
CVE-2026-20823 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 27 дней назад | |
CVE-2026-20822 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 27 дней назад | |
CVE-2026-20821 Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally. | CVSS3: 6.2 | 0% Низкий | 27 дней назад | |
CVE-2026-20820 Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 27 дней назад | |
CVE-2026-2081 A vulnerability was determined in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_password. This manipulation of the argument http_passwd causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. | CVSS3: 4.7 | 0% Низкий | 3 дня назад | |
CVE-2026-20819 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 27 дней назад | |
CVE-2026-20818 Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally. | CVSS3: 6.2 | 0% Низкий | 27 дней назад | |
CVE-2026-20817 Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 27 дней назад | |
CVE-2026-20816 Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 27 дней назад | |
CVE-2026-20815 Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 27 дней назад | |
CVE-2026-20814 Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 27 дней назад | |
CVE-2026-20812 Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network. | CVSS3: 6.5 | 0% Низкий | 27 дней назад | |
CVE-2026-20811 Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 27 дней назад |
Уязвимостей на страницу