Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 389 227

Количество 389 227

nvd логотип

CVE-2026-5828

5 месяцев назад

A vulnerability was found in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /functions/addcomment.php. The manipulation of the argument postid results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2026-58289

2 месяца назад

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 9
EPSS: Низкий
nvd логотип

CVE-2026-58288

2 месяца назад

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2026-58287

2 месяца назад

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2026-58286

2 месяца назад

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-58285

2 месяца назад

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2026-58284

2 месяца назад

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2026-58283

2 месяца назад

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-58282

2 месяца назад

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-58281

2 месяца назад

Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2026-5827

5 месяцев назад

A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the file /question-function.php. The manipulation of the argument content leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2026-58279

около 2 месяцев назад

Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-58278

2 месяца назад

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-58277

около 2 месяцев назад

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-58276

2 месяца назад

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-58275

около 2 месяцев назад

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
EPSS: Низкий
nvd логотип

CVE-2026-5826

5 месяцев назад

A flaw has been found in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /edit-category.php. Executing a manipulation of the argument Category can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-58266

2 месяца назад

Anki is a program for creating and reviewing flashcards. Prior to 25.09.4, Anki's webview-based pages communicate with the Rust backend using an internal localhost API, and user scripts included via iframes in the editor can access this API despite protections intended to block reviewer and editor scripts. A malicious imported card package with an embedded iframe can use exposed API methods such as getImageForOcclusion to read arbitrary files accessible to the Anki process and exfiltrate them over the network. This issue is fixed in version 25.09.4.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-58263

2 месяца назад

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. In versions prior to 4.12.28, the built-in clean-html sanitizer can be bypassed by a MathML/<style> carrier that hides a dangerous element from the sanitizer's element walk, so a no-interaction event handler survives into the editor value, potentially causing Mutation XSS. When an application supplies attacker-influenced HTML to the editor's value-set or insertion paths, the sanitized output still contains a live <img ... onload=...> (or another non-onerror handler such as onfocus). A consumer that renders that output (element.innerHTML = editor.value) executes the handler with no user interaction. This issue has been fixed in version 4.12.28.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2026-58262

около 1 месяца назад

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification counts the unused padding bits of the PubKeysBitmap toward the two-thirds validator quorum. These padding bits do not correspond to any validator and are ignored by the actual BLS aggregate-signature check, so a malicious or compromised block producer can set them to reach the required quorum while gathering fewer genuine validator signatures than the protocol demands. As a result, nodes that import or intercept the header accept it as correctly signed without a real two-thirds quorum, weakening consensus safety and undermining finality. This issue is fixed in version 1.7.20.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-5828

A vulnerability was found in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /functions/addcomment.php. The manipulation of the argument postid results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.

CVSS3: 7.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-58289

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 9
2%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58288

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.3
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58287

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.3
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58286

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 8.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58285

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.3
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58284

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.3
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58283

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 8.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58282

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 8.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58281

Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.3
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5827

A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the file /question-function.php. The manipulation of the argument content leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-58279

Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

CVSS3: 6.5
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-58278

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 5.4
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58277

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.8
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-58276

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 7.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58275

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-5826

A flaw has been found in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /edit-category.php. Executing a manipulation of the argument Category can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-58266

Anki is a program for creating and reviewing flashcards. Prior to 25.09.4, Anki's webview-based pages communicate with the Rust backend using an internal localhost API, and user scripts included via iframes in the editor can access this API despite protections intended to block reviewer and editor scripts. A malicious imported card package with an embedded iframe can use exposed API methods such as getImageForOcclusion to read arbitrary files accessible to the Anki process and exfiltrate them over the network. This issue is fixed in version 25.09.4.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58263

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. In versions prior to 4.12.28, the built-in clean-html sanitizer can be bypassed by a MathML/<style> carrier that hides a dangerous element from the sanitizer's element walk, so a no-interaction event handler survives into the editor value, potentially causing Mutation XSS. When an application supplies attacker-influenced HTML to the editor's value-set or insertion paths, the sanitized output still contains a live <img ... onload=...> (or another non-onerror handler such as onfocus). A consumer that renders that output (element.innerHTML = editor.value) executes the handler with no user interaction. This issue has been fixed in version 4.12.28.

CVSS3: 7.2
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58262

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification counts the unused padding bits of the PubKeysBitmap toward the two-thirds validator quorum. These padding bits do not correspond to any validator and are ignored by the actual BLS aggregate-signature check, so a malicious or compromised block producer can set them to reach the required quorum while gathering fewer genuine validator signatures than the protocol demands. As a result, nodes that import or intercept the header accept it as correctly signed without a real two-thirds quorum, weakening consensus safety and undermining finality. This issue is fixed in version 1.7.20.

0%
Низкий
около 1 месяца назад

Уязвимостей на страницу