Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 396 015

Количество 396 015

nvd логотип

CVE-2026-56181

2 месяца назад

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2026-5617

5 месяцев назад

The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the handle_return_to_admin() function trusting a client-controlled cookie (oclaup_original_admin) to determine which user to authenticate as, without any server-side verification that the cookie value was legitimately set during an admin-initiated user switch. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to administrator by setting the oclaup_original_admin cookie to an administrator's user ID and triggering the "Return to Admin" functionality.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-56179

около 1 месяца назад

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2026-56178

2 месяца назад

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-56177

14 дней назад

Use after free in Windows Server allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56176

2 месяца назад

Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56175

2 месяца назад

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56174

около 1 месяца назад

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56173

2 месяца назад

Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-56172

14 дней назад

Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-56171

2 месяца назад

Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-56170

2 месяца назад

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-5616

6 месяцев назад

A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/airag/JeecgBizToolsProvider.java of the component AI Chat Module. Such manipulation leads to missing authentication. The attack can be executed remotely. The name of the patch is b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39/2c1cc88b8d983868df8c520a343d6ff4369d9e59. It is best practice to apply a patch to resolve this issue. The project fixed the issue with a commit which shall be part of the next official release.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2026-56169

2 месяца назад

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-56168

2 месяца назад

Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-56167

2 месяца назад

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2026-56165

2 месяца назад

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-56164

2 месяца назад

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 5.3
EPSS: Средний
nvd логотип

CVE-2026-56163

2 месяца назад

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
EPSS: Низкий
nvd логотип

CVE-2026-56162

около 2 месяцев назад

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-56181

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

CVSS3: 8.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5617

The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the handle_return_to_admin() function trusting a client-controlled cookie (oclaup_original_admin) to determine which user to authenticate as, without any server-side verification that the cookie value was legitimately set during an admin-initiated user switch. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to administrator by setting the oclaup_original_admin cookie to an administrator's user ID and triggering the "Return to Admin" functionality.

CVSS3: 8.8
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-56179

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

CVSS3: 8.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-56178

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

CVSS3: 5.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56177

Use after free in Windows Server allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
14 дней назад
nvd логотип
CVE-2026-56176

Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56175

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56174

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-56173

Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56172

Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
14 дней назад
nvd логотип
CVE-2026-56171

Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.1
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56170

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5616

A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/airag/JeecgBizToolsProvider.java of the component AI Chat Module. Such manipulation leads to missing authentication. The attack can be executed remotely. The name of the patch is b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39/2c1cc88b8d983868df8c520a343d6ff4369d9e59. It is best practice to apply a patch to resolve this issue. The project fixed the issue with a commit which shall be part of the next official release.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-56169

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.1
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56168

Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.

CVSS3: 6.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56167

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56165

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56164

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 5.3
27%
Средний
2 месяца назад
nvd логотип
CVE-2026-56163

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56162

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
1%
Низкий
около 2 месяцев назад

Уязвимостей на страницу