Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 389 227

Количество 389 227

nvd логотип

CVE-2026-5830

5 месяцев назад

A vulnerability was identified in Tenda AC15 15.03.05.18. This affects the function websGetVar of the file /goform/SysToolChangePwd. Such manipulation of the argument oldPwd/newPwd/cfmPwd leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-58307

2 месяца назад

Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation. This issue affects Escargot: before 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2026-58306

2 месяца назад

Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before ef525f337fafddecde77a3c426212a84bb20cb98.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2026-58305

2 месяца назад

Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2026-58304

2 месяца назад

Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2026-58303

2 месяца назад

Stack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before b30b63fc63b403907d8137da1c65aaa4521fe74e.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2026-58302

2 месяца назад

rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads shared library modules via dlopen() by using a user-supplied module name. Insufficient validation of the module name allows path traversal, enabling an unprivileged local user to load an arbitrary shared library. Because the process retains elevated privileges during module loading, this results in local privilege escalation to root.

CVSS3: 8.4
EPSS: Низкий
nvd логотип

CVE-2026-58301

10 дней назад

When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server to initiate a connection to an attacker-controlled URL and transmit attacker-controlled data. This vulnerability affects Apache Shiro versions 2.x through 3.0.0 only in deployments that use the Jakarta EE integration module. Mitigation: Upgrade to version 3.0.1 or later, which fixes the issue. + Alternatively, you can set the `org.apache.shiro.form-resubmit-host` (String) and `org.apache.shiro.form-resubmit-port` (Integer) system properties to restrict the host and port that Shiro will connect to when resubmitting a form.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-58300

2 месяца назад

Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

CVSS3: 6.2
EPSS: Низкий
nvd логотип

CVE-2026-5829

5 месяцев назад

A vulnerability was determined in code-projects Simple IT Discussion Forum 1.0. The impacted element is an unknown function of the file /pages/content.php. This manipulation of the argument post_id causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2026-58299

2 месяца назад

Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-58298

2 месяца назад

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2026-58297

2 месяца назад

Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-58296

2 месяца назад

Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-58295

2 месяца назад

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2026-58294

2 месяца назад

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-58293

2 месяца назад

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-58292

2 месяца назад

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-58291

2 месяца назад

Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2026-58290

2 месяца назад

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-5830

A vulnerability was identified in Tenda AC15 15.03.05.18. This affects the function websGetVar of the file /goform/SysToolChangePwd. Such manipulation of the argument oldPwd/newPwd/cfmPwd leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.

CVSS3: 8.8
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-58307

Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation. This issue affects Escargot: before 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c.

CVSS3: 6.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58306

Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before ef525f337fafddecde77a3c426212a84bb20cb98.

CVSS3: 6.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58305

Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a.

CVSS3: 6.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58304

Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a.

CVSS3: 6.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58303

Stack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before b30b63fc63b403907d8137da1c65aaa4521fe74e.

CVSS3: 6.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58302

rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads shared library modules via dlopen() by using a user-supplied module name. Insufficient validation of the module name allows path traversal, enabling an unprivileged local user to load an arbitrary shared library. Because the process retains elevated privileges during module loading, this results in local privilege escalation to root.

CVSS3: 8.4
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58301

When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server to initiate a connection to an attacker-controlled URL and transmit attacker-controlled data. This vulnerability affects Apache Shiro versions 2.x through 3.0.0 only in deployments that use the Jakarta EE integration module. Mitigation: Upgrade to version 3.0.1 or later, which fixes the issue. + Alternatively, you can set the `org.apache.shiro.form-resubmit-host` (String) and `org.apache.shiro.form-resubmit-port` (Integer) system properties to restrict the host and port that Shiro will connect to when resubmitting a form.

CVSS3: 6.5
0%
Низкий
10 дней назад
nvd логотип
CVE-2026-58300

Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

CVSS3: 6.2
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5829

A vulnerability was determined in code-projects Simple IT Discussion Forum 1.0. The impacted element is an unknown function of the file /pages/content.php. This manipulation of the argument post_id causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

CVSS3: 7.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-58299

Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.

CVSS3: 7.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58298

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 7.2
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58297

Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.1
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58296

Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.1
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58295

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

CVSS3: 8.3
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58294

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 7.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58293

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.1
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58292

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 7.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58291

Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.1
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58290

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 7.5
0%
Низкий
2 месяца назад

Уязвимостей на страницу