Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 390 627

Количество 390 627

nvd логотип

CVE-2026-5713

5 месяцев назад

The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used to read and write addresses in a privileged process if that process connected to a malicious or "infected" Python process via the remote debugging feature. This vulnerability requires persistently and repeatedly connecting to the process to be exploited, even after the connecting process crashes with high likelihood due to ASLR.

EPSS: Низкий
nvd логотип

CVE-2026-5712

5 месяцев назад

This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing.

CVSS3: 8
EPSS: Низкий
nvd логотип

CVE-2026-5711

5 месяцев назад

The Post Blocks & Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliderStyle' block attribute in the Posts Slider block in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2026-57111

2 месяца назад

Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows a remote attacker controlling a web page visited by an authorized user to read responses from and issue cross-origin requests to administrative REST endpoints via a cross-origin request from an arbitrary origin, since the filter unconditionally returns Access-Control-Allow-Origin: * together with Access-Control-Allow-Credentials: true and reflects arbitrary Access-Control-Request-Method / Access-Control-Request-Headers values in preflight responses. Users are recommended to upgrade to version 2.0.1, which fixes this issue.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-5710

5 месяцев назад

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versions up to and including 1.3.9.6. This is due to the plugin using client-supplied mfile[] POST values as the source of truth for email attachment selection without performing any server-side upload provenance check, path canonicalization, or directory containment boundary enforcement. In dnd_wpcf7_posted_data(), each user-submitted filename is directly appended to the plugin's upload URL without sanitization. In dnd_cf7_mail_components(), the URL is converted back to a filesystem path using str_replace() and only file_exists() is used as the acceptance check before attaching the file to the outgoing CF7 email. This makes it possible for unauthenticated attackers to read and exfiltrate arbitrary files readable by the web server process via path traversal sequences in the mfile[] parameter, with files being disclosed as email attachments. No

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-57108

2 месяца назад

Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-57107

2 месяца назад

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-57106

около 2 месяцев назад

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
EPSS: Низкий
nvd логотип

CVE-2026-57105

около 1 месяца назад

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVSS3: 8
EPSS: Низкий
nvd логотип

CVE-2026-57104

около 1 месяца назад

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-57102

2 месяца назад

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-57101

2 месяца назад

Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57100

2 месяца назад

Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

CVSS3: 9.9
EPSS: Низкий
nvd логотип

CVE-2026-5709

5 месяцев назад

Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via crafted input when using the FileBrowser functionality. To remediate this issue, users are advised to upgrade to RES version 2026.03 or apply the corresponding mitigation patch to their existing environment.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-57099

6 дней назад

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-57098

6 дней назад

Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-57097

2 месяца назад

Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2026-57096

2 месяца назад

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-57095

2 месяца назад

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.

CVSS3: 6.2
EPSS: Низкий
nvd логотип

CVE-2026-57094

2 месяца назад

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-5713

The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used to read and write addresses in a privileged process if that process connected to a malicious or "infected" Python process via the remote debugging feature. This vulnerability requires persistently and repeatedly connecting to the process to be exploited, even after the connecting process crashes with high likelihood due to ASLR.

0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-5712

This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing.

CVSS3: 8
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-5711

The Post Blocks & Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliderStyle' block attribute in the Posts Slider block in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-57111

Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows a remote attacker controlling a web page visited by an authorized user to read responses from and issue cross-origin requests to administrative REST endpoints via a cross-origin request from an arbitrary origin, since the filter unconditionally returns Access-Control-Allow-Origin: * together with Access-Control-Allow-Credentials: true and reflects arbitrary Access-Control-Request-Method / Access-Control-Request-Headers values in preflight responses. Users are recommended to upgrade to version 2.0.1, which fixes this issue.

CVSS3: 7.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5710

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versions up to and including 1.3.9.6. This is due to the plugin using client-supplied mfile[] POST values as the source of truth for email attachment selection without performing any server-side upload provenance check, path canonicalization, or directory containment boundary enforcement. In dnd_wpcf7_posted_data(), each user-submitted filename is directly appended to the plugin's upload URL without sanitization. In dnd_cf7_mail_components(), the URL is converted back to a filesystem path using str_replace() and only file_exists() is used as the acceptance check before attaching the file to the outgoing CF7 email. This makes it possible for unauthenticated attackers to read and exfiltrate arbitrary files readable by the web server process via path traversal sequences in the mfile[] parameter, with files being disclosed as email attachments. No

CVSS3: 7.5
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-57108

Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57107

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57106

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57105

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVSS3: 8
1%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-57104

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 8.8
1%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-57102

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

CVSS3: 8.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57101

Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57100

Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

CVSS3: 9.9
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5709

Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via crafted input when using the FileBrowser functionality. To remediate this issue, users are advised to upgrade to RES version 2026.03 or apply the corresponding mitigation patch to their existing environment.

CVSS3: 8.8
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-57099

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
1%
Низкий
6 дней назад
nvd логотип
CVE-2026-57098

Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.5
1%
Низкий
6 дней назад
nvd логотип
CVE-2026-57097

Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.

CVSS3: 6.4
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57096

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57095

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.

CVSS3: 6.2
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57094

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
1%
Низкий
2 месяца назад

Уязвимостей на страницу