Количество 390 981
Количество 390 981
CVE-2026-56188
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.
CVE-2026-56187
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-56186
Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.
CVE-2026-56185
Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
CVE-2026-56184
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-56183
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-56182
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-56181
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
CVE-2026-5617
The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the handle_return_to_admin() function trusting a client-controlled cookie (oclaup_original_admin) to determine which user to authenticate as, without any server-side verification that the cookie value was legitimately set during an admin-initiated user switch. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to administrator by setting the oclaup_original_admin cookie to an administrator's user ID and triggering the "Return to Admin" functionality.
CVE-2026-56179
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
CVE-2026-56178
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
CVE-2026-56177
Use after free in Windows Server allows an authorized attacker to elevate privileges locally.
CVE-2026-56176
Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
CVE-2026-56175
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-56174
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
CVE-2026-56173
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
CVE-2026-56172
Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.
CVE-2026-56171
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-56170
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-5616
A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/airag/JeecgBizToolsProvider.java of the component AI Chat Module. Such manipulation leads to missing authentication. The attack can be executed remotely. The name of the patch is b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39/2c1cc88b8d983868df8c520a343d6ff4369d9e59. It is best practice to apply a patch to resolve this issue. The project fixed the issue with a commit which shall be part of the next official release.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-56188 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network. | CVSS3: 9.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-56187 Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 2 месяца назад | |
CVE-2026-56186 Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network. | CVSS3: 8.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-56185 Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network. | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-56184 Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-56183 Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 2 месяца назад | |
CVE-2026-56182 Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-56181 Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. | CVSS3: 8.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-5617 The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the handle_return_to_admin() function trusting a client-controlled cookie (oclaup_original_admin) to determine which user to authenticate as, without any server-side verification that the cookie value was legitimately set during an admin-initiated user switch. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to administrator by setting the oclaup_original_admin cookie to an administrator's user ID and triggering the "Return to Admin" functionality. | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад | |
CVE-2026-56179 Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. | CVSS3: 8.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-56178 Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. | CVSS3: 5.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-56177 Use after free in Windows Server allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 7 дней назад | |
CVE-2026-56176 Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-56175 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-56174 Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-56173 Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 2 месяца назад | |
CVE-2026-56172 Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 7 дней назад | |
CVE-2026-56171 Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network. | CVSS3: 7.1 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-56170 Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-5616 A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/airag/JeecgBizToolsProvider.java of the component AI Chat Module. Such manipulation leads to missing authentication. The attack can be executed remotely. The name of the patch is b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39/2c1cc88b8d983868df8c520a343d6ff4369d9e59. It is best practice to apply a patch to resolve this issue. The project fixed the issue with a commit which shall be part of the next official release. | CVSS3: 7.3 | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу