Количество 25 045
Количество 25 045
CVE-2026-48526
PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed
CVE-2026-48525
PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
CVE-2026-48524
PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
CVE-2026-48522
PyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, data: schemes
CVE-2026-4833
Orc discount Markdown markdown.c compile recursion
CVE-2026-48142
NGINX ngx_http_charset_module vulnerability
CVE-2026-4786
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
CVE-2026-47784
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.
CVE-2026-47783
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.
CVE-2026-47770
jq: stack overflow in deep structural equality
CVE-2026-4775
Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing
CVE-2026-47729
Squid: Memory disclosure in FTP gateway
CVE-2026-47656
Windows Boot Manager Security Feature Bypass Vulnerability
CVE-2026-47655
Microsoft Graph Information Disclosure Vulnerability
CVE-2026-47654
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-47653
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-47652
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-47648
Windows Storage Elevation of Privilege Vulnerability
CVE-2026-47647
Dynamics 365 Elevation of Privilege Vulnerability
CVE-2026-47646
Dynamics 365 Customer Voice Spoofing Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-48526 PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed | 0% Низкий | 12 дней назад | ||
CVE-2026-48525 PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS | 0% Низкий | 12 дней назад | ||
CVE-2026-48524 PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS) | 0% Низкий | 12 дней назад | ||
CVE-2026-48522 PyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, data: schemes | 0% Низкий | 12 дней назад | ||
CVE-2026-4833 Orc discount Markdown markdown.c compile recursion | 0% Низкий | 3 месяца назад | ||
CVE-2026-48142 NGINX ngx_http_charset_module vulnerability | CVSS3: 4.8 | 1% Низкий | около 1 месяца назад | |
CVE-2026-4786 Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open() | 0% Низкий | 3 месяца назад | ||
CVE-2026-47784 In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass. | CVSS3: 8.1 | 1% Низкий | 3 месяца назад | |
CVE-2026-47783 In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass. | CVSS3: 8.1 | 1% Низкий | 3 месяца назад | |
CVE-2026-47770 jq: stack overflow in deep structural equality | CVSS3: 5.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-4775 Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing | CVSS3: 7.8 | 1% Низкий | 4 месяца назад | |
CVE-2026-47729 Squid: Memory disclosure in FTP gateway | CVSS3: 6.5 | 2% Низкий | 18 дней назад | |
CVE-2026-47656 Windows Boot Manager Security Feature Bypass Vulnerability | CVSS3: 7.9 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-47655 Microsoft Graph Information Disclosure Vulnerability | 1% Низкий | 2 месяца назад | ||
CVE-2026-47654 Remote Desktop Client Remote Code Execution Vulnerability | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-47653 Remote Desktop Client Remote Code Execution Vulnerability | CVSS3: 8.8 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-47652 Windows Hyper-V Remote Code Execution Vulnerability | CVSS3: 8.2 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-47648 Windows Storage Elevation of Privilege Vulnerability | CVSS3: 7 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-47647 Dynamics 365 Elevation of Privilege Vulnerability | 1% Низкий | около 2 месяцев назад | ||
CVE-2026-47646 Dynamics 365 Customer Voice Spoofing Vulnerability | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу