Количество 393 454
Количество 393 454
CVE-2026-5798
Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ endpoint, through manipulation of the ‘employeeID’ parameter. An authenticated attacker could exploit this vulnerability to access information about any employee (first names, last names, roles, job titles, and vacation records, among others) by modifying that identifier in requests sent to the server.
CVE-2026-57989
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
CVE-2026-57988
Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-57987
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-57986
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-57985
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-57984
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-57983
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-57982
Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.
CVE-2026-57981
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-57980
Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.
CVE-2026-5797
The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to insufficient input sanitization and the execution of do_shortcode() on user-submitted quiz answer text. User-submitted answers pass through sanitize_text_field() and htmlspecialchars(), which only strip HTML tags but do not encode or remove shortcode brackets [ and ]. When quiz results are displayed, the plugin calls do_shortcode() on the entire results page output (including user answers), causing any injected shortcodes to be executed. This makes it possible for unauthenticated attackers to inject arbitrary WordPress shortcodes such as [qsm_result id=X] to access other users' quiz submissions without authorization, as the qsm_result shortcode lacks any authorization checks.
CVE-2026-57979
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-57978
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-57977
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-57976
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
CVE-2026-57975
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-57974
Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-57973
Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally.
CVE-2026-5796
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with Reporter-level group permissions to view package metadata from projects with the Package Registry disabled due to incorrect authorization checks in the group packages feature.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-5798 Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ endpoint, through manipulation of the ‘employeeID’ parameter. An authenticated attacker could exploit this vulnerability to access information about any employee (first names, last names, roles, job titles, and vacation records, among others) by modifying that identifier in requests sent to the server. | 0% Низкий | 4 месяца назад | ||
CVE-2026-57989 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | CVSS3: 7.4 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-57988 Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | CVSS3: 7.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-57987 Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-57986 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-57985 Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | CVSS3: 7.6 | 1% Низкий | 2 месяца назад | |
CVE-2026-57984 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-57983 Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | CVSS3: 8.7 | 1% Низкий | 2 месяца назад | |
CVE-2026-57982 Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network. | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-57981 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | CVSS3: 8.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-57980 Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. | CVSS3: 5.4 | 0% Низкий | 2 месяца назад | |
CVE-2026-5797 The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to insufficient input sanitization and the execution of do_shortcode() on user-submitted quiz answer text. User-submitted answers pass through sanitize_text_field() and htmlspecialchars(), which only strip HTML tags but do not encode or remove shortcode brackets [ and ]. When quiz results are displayed, the plugin calls do_shortcode() on the entire results page output (including user answers), causing any injected shortcodes to be executed. This makes it possible for unauthenticated attackers to inject arbitrary WordPress shortcodes such as [qsm_result id=X] to access other users' quiz submissions without authorization, as the qsm_result shortcode lacks any authorization checks. | CVSS3: 5.3 | 1% Низкий | 5 месяцев назад | |
CVE-2026-57979 Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-57978 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | CVSS3: 5.4 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-57977 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | CVSS3: 7.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-57976 Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-57975 Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-57974 Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | CVSS3: 8.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-57973 Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally. | CVSS3: 6.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-5796 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with Reporter-level group permissions to view package metadata from projects with the Package Registry disabled due to incorrect authorization checks in the group packages feature. | CVSS3: 4.3 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу