Количество 387 322
Количество 387 322
CVE-2026-56169
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-56168
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.
CVE-2026-56167
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
CVE-2026-56165
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
CVE-2026-56164
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56163
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56162
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56161
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
CVE-2026-56160
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
CVE-2026-5615
A weakness has been identified in givanz Vvvebjs up to 2.0.5. The affected element is an unknown function of the file upload.php of the component File Upload Endpoint. This manipulation of the argument uploadAllowExtensions causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. Patch name: 8cac22cff99b8bc701c408aa8e887fa702755336. Applying a patch is the recommended action to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
CVE-2026-56159
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-56157
Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-56156
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-56155
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
CVE-2026-56152
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
CVE-2026-56151
Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submit a specially crafted Fleet policy input that is not correctly validated, which can render Fleet agent, server, and policy management functionality unavailable.
CVE-2026-56150
Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specially crafted request to an upload endpoint that causes excessive memory consumption, which may render Fleet Server unavailable.
CVE-2026-5614
A security flaw has been discovered in Belkin F9K1015 1.00.10. Impacted is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument webpage results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-56149
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted machine learning request that causes excessive memory consumption, which may render the affected node unavailable.
CVE-2026-56148
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query that causes excessive resource consumption while the request is processed, which may render the affected node unavailable.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-56169 Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | CVSS3: 8.1 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-56168 Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network. | CVSS3: 6.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-56167 Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. | CVSS3: 8.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-56165 Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. | CVSS3: 9.8 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-56164 Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. | CVSS3: 5.3 | 27% Средний | около 2 месяцев назад | |
CVE-2026-56163 Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | CVSS3: 10 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-56162 Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | CVSS3: 10 | 1% Низкий | около 1 месяца назад | |
CVE-2026-56161 Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. | CVSS3: 9.6 | 0% Низкий | около 1 месяца назад | |
CVE-2026-56160 Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. | CVSS3: 9.1 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-5615 A weakness has been identified in givanz Vvvebjs up to 2.0.5. The affected element is an unknown function of the file upload.php of the component File Upload Endpoint. This manipulation of the argument uploadAllowExtensions causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. Patch name: 8cac22cff99b8bc701c408aa8e887fa702755336. Applying a patch is the recommended action to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. | CVSS3: 4.3 | 1% Низкий | 5 месяцев назад | |
CVE-2026-56159 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | CVSS3: 9.8 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-56157 Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | CVSS3: 5.4 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-56156 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-56155 Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-56152 Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view. | CVSS3: 5.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-56151 Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submit a specially crafted Fleet policy input that is not correctly validated, which can render Fleet agent, server, and policy management functionality unavailable. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-56150 Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specially crafted request to an upload endpoint that causes excessive memory consumption, which may render Fleet Server unavailable. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-5614 A security flaw has been discovered in Belkin F9K1015 1.00.10. Impacted is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument webpage results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 8.8 | 1% Низкий | 5 месяцев назад | |
CVE-2026-56149 Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted machine learning request that causes excessive memory consumption, which may render the affected node unavailable. | CVSS3: 4.9 | 1% Низкий | 2 месяца назад | |
CVE-2026-56148 Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query that causes excessive resource consumption while the request is processed, which may render the affected node unavailable. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу