Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 387 322

Количество 387 322

nvd логотип

CVE-2026-56169

около 2 месяцев назад

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-56168

около 2 месяцев назад

Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-56167

около 2 месяцев назад

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2026-56165

около 2 месяцев назад

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-56164

около 2 месяцев назад

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 5.3
EPSS: Средний
nvd логотип

CVE-2026-56163

около 2 месяцев назад

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
EPSS: Низкий
nvd логотип

CVE-2026-56162

около 1 месяца назад

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
EPSS: Низкий
nvd логотип

CVE-2026-56161

около 1 месяца назад

Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

CVSS3: 9.6
EPSS: Низкий
nvd логотип

CVE-2026-56160

около 2 месяцев назад

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-5615

5 месяцев назад

A weakness has been identified in givanz Vvvebjs up to 2.0.5. The affected element is an unknown function of the file upload.php of the component File Upload Endpoint. This manipulation of the argument uploadAllowExtensions causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. Patch name: 8cac22cff99b8bc701c408aa8e887fa702755336. Applying a patch is the recommended action to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-56159

около 2 месяцев назад

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-56157

около 2 месяцев назад

Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-56156

около 2 месяцев назад

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56155

около 2 месяцев назад

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56152

2 месяца назад

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-56151

2 месяца назад

Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submit a specially crafted Fleet policy input that is not correctly validated, which can render Fleet agent, server, and policy management functionality unavailable.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-56150

2 месяца назад

Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specially crafted request to an upload endpoint that causes excessive memory consumption, which may render Fleet Server unavailable.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-5614

5 месяцев назад

A security flaw has been discovered in Belkin F9K1015 1.00.10. Impacted is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument webpage results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-56149

2 месяца назад

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted machine learning request that causes excessive memory consumption, which may render the affected node unavailable.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2026-56148

2 месяца назад

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query that causes excessive resource consumption while the request is processed, which may render the affected node unavailable.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-56169

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.1
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56168

Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.

CVSS3: 6.5
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56167

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56165

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56164

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 5.3
27%
Средний
около 2 месяцев назад
nvd логотип
CVE-2026-56163

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56162

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
1%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-56161

Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

CVSS3: 9.6
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-56160

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

CVSS3: 9.1
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-5615

A weakness has been identified in givanz Vvvebjs up to 2.0.5. The affected element is an unknown function of the file upload.php of the component File Upload Endpoint. This manipulation of the argument uploadAllowExtensions causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. Patch name: 8cac22cff99b8bc701c408aa8e887fa702755336. Applying a patch is the recommended action to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CVSS3: 4.3
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-56159

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56157

Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56156

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56155

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56152

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.

CVSS3: 5.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56151

Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submit a specially crafted Fleet policy input that is not correctly validated, which can render Fleet agent, server, and policy management functionality unavailable.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56150

Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specially crafted request to an upload endpoint that causes excessive memory consumption, which may render Fleet Server unavailable.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5614

A security flaw has been discovered in Belkin F9K1015 1.00.10. Impacted is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument webpage results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-56149

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted machine learning request that causes excessive memory consumption, which may render the affected node unavailable.

CVSS3: 4.9
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56148

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query that causes excessive resource consumption while the request is processed, which may render the affected node unavailable.

CVSS3: 6.5
0%
Низкий
2 месяца назад

Уязвимостей на страницу