Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 395 605

Количество 395 605

nvd логотип

CVE-2026-56168

2 месяца назад

Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-56167

2 месяца назад

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2026-56165

2 месяца назад

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-56164

2 месяца назад

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 5.3
EPSS: Средний
nvd логотип

CVE-2026-56163

около 2 месяцев назад

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
EPSS: Низкий
nvd логотип

CVE-2026-56162

около 2 месяцев назад

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
EPSS: Низкий
nvd логотип

CVE-2026-56161

около 2 месяцев назад

Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

CVSS3: 9.6
EPSS: Низкий
nvd логотип

CVE-2026-56160

2 месяца назад

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-5615

6 месяцев назад

A weakness has been identified in givanz Vvvebjs up to 2.0.5. The affected element is an unknown function of the file upload.php of the component File Upload Endpoint. This manipulation of the argument uploadAllowExtensions causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. Patch name: 8cac22cff99b8bc701c408aa8e887fa702755336. Applying a patch is the recommended action to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-56159

2 месяца назад

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-56157

2 месяца назад

Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-56156

2 месяца назад

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56155

2 месяца назад

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56152

3 месяца назад

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-56151

3 месяца назад

Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submit a specially crafted Fleet policy input that is not correctly validated, which can render Fleet agent, server, and policy management functionality unavailable.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-56150

3 месяца назад

Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specially crafted request to an upload endpoint that causes excessive memory consumption, which may render Fleet Server unavailable.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-5614

6 месяцев назад

A security flaw has been discovered in Belkin F9K1015 1.00.10. Impacted is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument webpage results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-56149

3 месяца назад

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted machine learning request that causes excessive memory consumption, which may render the affected node unavailable.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2026-56148

3 месяца назад

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query that causes excessive resource consumption while the request is processed, which may render the affected node unavailable.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-56147

2 месяца назад

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity compromise via Privilege Abuse (CAPEC-122). An inconsistency in Kibana's file access authorization logic allows a low-privileged authenticated user to retrieve, modify, and delete case attachments that belong to feature areas they are not authorized to access. Because the access control check and the resource retrieval use different resolution mechanisms, an authenticated attacker with limited file management permissions can obtain the contents of, modify, or delete protected case attachments — such as those associated with Security Solution cases — without holding the privileges required to access those features.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-56168

Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.

CVSS3: 6.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56167

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56165

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56164

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 5.3
27%
Средний
2 месяца назад
nvd логотип
CVE-2026-56163

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56162

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56161

Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

CVSS3: 9.6
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56160

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

CVSS3: 9.1
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5615

A weakness has been identified in givanz Vvvebjs up to 2.0.5. The affected element is an unknown function of the file upload.php of the component File Upload Endpoint. This manipulation of the argument uploadAllowExtensions causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. Patch name: 8cac22cff99b8bc701c408aa8e887fa702755336. Applying a patch is the recommended action to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CVSS3: 4.3
1%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-56159

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56157

Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVSS3: 5.4
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56156

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56155

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56152

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.

CVSS3: 5.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56151

Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submit a specially crafted Fleet policy input that is not correctly validated, which can render Fleet agent, server, and policy management functionality unavailable.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56150

Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specially crafted request to an upload endpoint that causes excessive memory consumption, which may render Fleet Server unavailable.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-5614

A security flaw has been discovered in Belkin F9K1015 1.00.10. Impacted is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument webpage results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
1%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-56149

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted machine learning request that causes excessive memory consumption, which may render the affected node unavailable.

CVSS3: 4.9
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56148

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query that causes excessive resource consumption while the request is processed, which may render the affected node unavailable.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56147

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity compromise via Privilege Abuse (CAPEC-122). An inconsistency in Kibana's file access authorization logic allows a low-privileged authenticated user to retrieve, modify, and delete case attachments that belong to feature areas they are not authorized to access. Because the access control check and the resource retrieval use different resolution mechanisms, an authenticated attacker with limited file management permissions can obtain the contents of, modify, or delete protected case attachments — such as those associated with Security Solution cases — without holding the privileges required to access those features.

CVSS3: 7.1
0%
Низкий
2 месяца назад

Уязвимостей на страницу