Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 396 015

Количество 396 015

nvd логотип

CVE-2026-56207

13 дней назад

Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are recommended to upgrade to version 4.5.2, which fixes this issue.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-5619

6 месяцев назад

A flaw has been found in Braffolk mcp-summarization-functions up to 0.1.5. This impacts an unknown function of the file src/server/mcp-server.ts of the component summarize_command. Executing a manipulation of the argument command can lead to os command injection. The attack requires local access. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-56198

14 дней назад

Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56197

2 месяца назад

Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-56196

2 месяца назад

Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-56195

2 месяца назад

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-56194

2 месяца назад

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-56193

2 месяца назад

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-56192

2 месяца назад

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-56191

2 месяца назад

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

CVSS3: 10
EPSS: Низкий
nvd логотип

CVE-2026-56190

2 месяца назад

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-5618

6 месяцев назад

A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake/shareCheck. Performing a manipulation of the argument siteFrom/siteTo results in server-side request forgery. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is reported as difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2026-56189

2 месяца назад

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56188

2 месяца назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-56187

2 месяца назад

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-56186

2 месяца назад

Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-56185

2 месяца назад

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-56184

2 месяца назад

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-56183

2 месяца назад

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-56182

2 месяца назад

Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-56207

Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are recommended to upgrade to version 4.5.2, which fixes this issue.

CVSS3: 9.8
0%
Низкий
13 дней назад
nvd логотип
CVE-2026-5619

A flaw has been found in Braffolk mcp-summarization-functions up to 0.1.5. This impacts an unknown function of the file src/server/mcp-server.ts of the component summarize_command. Executing a manipulation of the argument command can lead to os command injection. The attack requires local access. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
1%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-56198

Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
14 дней назад
nvd логотип
CVE-2026-56197

Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.

CVSS3: 8.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56196

Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.

CVSS3: 8.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56195

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVSS3: 5.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56194

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56193

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56192

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVSS3: 5.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56191

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

CVSS3: 10
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56190

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5618

A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake/shareCheck. Performing a manipulation of the argument siteFrom/siteTo results in server-side request forgery. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is reported as difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.6
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-56189

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56188

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56187

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56186

Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.

CVSS3: 8.1
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56185

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

CVSS3: 6.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56184

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56183

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56182

Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 месяца назад

Уязвимостей на страницу