Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 390 981

Количество 390 981

nvd логотип

CVE-2026-56188

2 месяца назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-56187

2 месяца назад

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-56186

2 месяца назад

Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-56185

2 месяца назад

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-56184

2 месяца назад

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-56183

2 месяца назад

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-56182

2 месяца назад

Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56181

2 месяца назад

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2026-5617

5 месяцев назад

The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the handle_return_to_admin() function trusting a client-controlled cookie (oclaup_original_admin) to determine which user to authenticate as, without any server-side verification that the cookie value was legitimately set during an admin-initiated user switch. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to administrator by setting the oclaup_original_admin cookie to an administrator's user ID and triggering the "Return to Admin" functionality.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-56179

около 1 месяца назад

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2026-56178

2 месяца назад

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-56177

7 дней назад

Use after free in Windows Server allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56176

2 месяца назад

Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56175

2 месяца назад

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56174

около 1 месяца назад

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56173

2 месяца назад

Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-56172

7 дней назад

Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56171

около 2 месяцев назад

Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-56170

2 месяца назад

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-5616

5 месяцев назад

A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/airag/JeecgBizToolsProvider.java of the component AI Chat Module. Such manipulation leads to missing authentication. The attack can be executed remotely. The name of the patch is b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39/2c1cc88b8d983868df8c520a343d6ff4369d9e59. It is best practice to apply a patch to resolve this issue. The project fixed the issue with a commit which shall be part of the next official release.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-56188

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56187

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56186

Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.

CVSS3: 8.1
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56185

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

CVSS3: 6.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56184

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56183

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56182

Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56181

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

CVSS3: 8.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5617

The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the handle_return_to_admin() function trusting a client-controlled cookie (oclaup_original_admin) to determine which user to authenticate as, without any server-side verification that the cookie value was legitimately set during an admin-initiated user switch. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to administrator by setting the oclaup_original_admin cookie to an administrator's user ID and triggering the "Return to Admin" functionality.

CVSS3: 8.8
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-56179

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

CVSS3: 8.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-56178

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

CVSS3: 5.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56177

Use after free in Windows Server allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
7 дней назад
nvd логотип
CVE-2026-56176

Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56175

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56174

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-56173

Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56172

Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
7 дней назад
nvd логотип
CVE-2026-56171

Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.1
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56170

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5616

A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/airag/JeecgBizToolsProvider.java of the component AI Chat Module. Such manipulation leads to missing authentication. The attack can be executed remotely. The name of the patch is b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39/2c1cc88b8d983868df8c520a343d6ff4369d9e59. It is best practice to apply a patch to resolve this issue. The project fixed the issue with a commit which shall be part of the next official release.

CVSS3: 7.3
0%
Низкий
5 месяцев назад

Уязвимостей на страницу