Количество 396 015
Количество 396 015
CVE-2026-56207
Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are recommended to upgrade to version 4.5.2, which fixes this issue.
CVE-2026-5619
A flaw has been found in Braffolk mcp-summarization-functions up to 0.1.5. This impacts an unknown function of the file src/server/mcp-server.ts of the component summarize_command. Executing a manipulation of the argument command can lead to os command injection. The attack requires local access. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-56198
Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.
CVE-2026-56197
Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.
CVE-2026-56196
Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
CVE-2026-56195
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-56194
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.
CVE-2026-56193
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-56192
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-56191
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
CVE-2026-56190
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
CVE-2026-5618
A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake/shareCheck. Performing a manipulation of the argument siteFrom/siteTo results in server-side request forgery. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is reported as difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-56189
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
CVE-2026-56188
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.
CVE-2026-56187
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-56186
Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.
CVE-2026-56185
Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
CVE-2026-56184
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-56183
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-56182
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-56207 Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are recommended to upgrade to version 4.5.2, which fixes this issue. | CVSS3: 9.8 | 0% Низкий | 13 дней назад | |
CVE-2026-5619 A flaw has been found in Braffolk mcp-summarization-functions up to 0.1.5. This impacts an unknown function of the file src/server/mcp-server.ts of the component summarize_command. Executing a manipulation of the argument command can lead to os command injection. The attack requires local access. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 5.3 | 1% Низкий | 6 месяцев назад | |
CVE-2026-56198 Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 14 дней назад | |
CVE-2026-56197 Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network. | CVSS3: 8.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-56196 Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network. | CVSS3: 8.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-56195 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | CVSS3: 5.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-56194 Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network. | CVSS3: 8.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-56193 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-56192 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | CVSS3: 5.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-56191 Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. | CVSS3: 10 | 1% Низкий | 2 месяца назад | |
CVE-2026-56190 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. | CVSS3: 9.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-5618 A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake/shareCheck. Performing a manipulation of the argument siteFrom/siteTo results in server-side request forgery. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is reported as difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 5.6 | 0% Низкий | 6 месяцев назад | |
CVE-2026-56189 Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-56188 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network. | CVSS3: 9.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-56187 Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 2 месяца назад | |
CVE-2026-56186 Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network. | CVSS3: 8.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-56185 Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network. | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-56184 Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-56183 Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 2 месяца назад | |
CVE-2026-56182 Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу