Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 387 322

Количество 387 322

nvd логотип

CVE-2026-5618

5 месяцев назад

A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake/shareCheck. Performing a manipulation of the argument siteFrom/siteTo results in server-side request forgery. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is reported as difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2026-56189

около 2 месяцев назад

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56188

около 2 месяцев назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-56187

около 2 месяцев назад

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-56186

около 2 месяцев назад

Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-56185

около 2 месяцев назад

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-56184

около 2 месяцев назад

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-56183

около 2 месяцев назад

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-56182

около 2 месяцев назад

Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56181

около 2 месяцев назад

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2026-5617

5 месяцев назад

The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the handle_return_to_admin() function trusting a client-controlled cookie (oclaup_original_admin) to determine which user to authenticate as, without any server-side verification that the cookie value was legitimately set during an admin-initiated user switch. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to administrator by setting the oclaup_original_admin cookie to an administrator's user ID and triggering the "Return to Admin" functionality.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-56179

29 дней назад

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2026-56178

около 2 месяцев назад

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-56176

около 2 месяцев назад

Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56175

около 2 месяцев назад

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56174

29 дней назад

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56173

около 2 месяцев назад

Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-56171

около 2 месяцев назад

Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-56170

около 2 месяцев назад

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-5616

5 месяцев назад

A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/airag/JeecgBizToolsProvider.java of the component AI Chat Module. Such manipulation leads to missing authentication. The attack can be executed remotely. The name of the patch is b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39/2c1cc88b8d983868df8c520a343d6ff4369d9e59. It is best practice to apply a patch to resolve this issue. The project fixed the issue with a commit which shall be part of the next official release.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-5618

A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake/shareCheck. Performing a manipulation of the argument siteFrom/siteTo results in server-side request forgery. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is reported as difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.6
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-56189

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56188

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56187

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56186

Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.

CVSS3: 8.1
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56185

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

CVSS3: 6.5
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56184

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56183

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56182

Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56181

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

CVSS3: 8.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-5617

The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the handle_return_to_admin() function trusting a client-controlled cookie (oclaup_original_admin) to determine which user to authenticate as, without any server-side verification that the cookie value was legitimately set during an admin-initiated user switch. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to administrator by setting the oclaup_original_admin cookie to an administrator's user ID and triggering the "Return to Admin" functionality.

CVSS3: 8.8
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-56179

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

CVSS3: 8.3
0%
Низкий
29 дней назад
nvd логотип
CVE-2026-56178

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

CVSS3: 5.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56176

Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56175

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56174

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
29 дней назад
nvd логотип
CVE-2026-56173

Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56171

Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.1
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56170

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-5616

A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/airag/JeecgBizToolsProvider.java of the component AI Chat Module. Such manipulation leads to missing authentication. The attack can be executed remotely. The name of the patch is b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39/2c1cc88b8d983868df8c520a343d6ff4369d9e59. It is best practice to apply a patch to resolve this issue. The project fixed the issue with a commit which shall be part of the next official release.

CVSS3: 7.3
0%
Низкий
5 месяцев назад

Уязвимостей на страницу