Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 396 015

Количество 396 015

nvd логотип

CVE-2026-55067

26 дней назад

Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket} allows the request body project_view_id value to be mass assigned by Bucket.Update in pkg/models/kanban.go. The permission check validates that the bucket currently belongs to the URL project and view but does not validate the body selected destination view, allowing any authenticated user to relocate an attacker-owned bucket into another tenant’s Kanban view. The injected bucket retains attacker-controlled content and ownership, enabling cross-tenant defacement. This issue is fixed in version 2.4.0.

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2026-55066

26 дней назад

Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}/tasks accepts a body supplied task_id but TaskBucket.CanUpdate in pkg/models/kanban_task_bucket.go authorizes only the project, view, and bucket from the URL. updateTaskBucket then calls Task.ReadOne without a separate task permission check, returns the victim task contents, and can update the task done state when the attacker chooses a done bucket. Because task identifiers are global sequential values, an authenticated user can enumerate cross-tenant tasks and modify their completion metadata through both the v1 and v2 routes that share this model. This issue is fixed in version 2.4.0.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-55065

26 дней назад

Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view identifier from another project while authorizing only against an attacker-controlled project identifier. ProjectView.CanDelete in pkg/models/project_view_permissions.go does not establish that the view belongs to the path project, and ProjectView.Delete in pkg/models/project_view.go continues after the scoped project_views delete affects no rows. Its subsequent deletes select task_buckets and task_positions only by project_view_id, allowing cross-tenant destruction of Kanban assignments and ordering while leaving the victim view and tasks intact. This issue is fixed in version 2.4.0.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-55064

26 дней назад

Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin permission on a shared child project can detach it from its parent hierarchy by submitting parent_project_id equal to 0 to POST /api/v1/projects/{project}. The Project.CanUpdate authorization check in pkg/models/project_permissions.go and UpdateProject logic in pkg/models/project.go only gate nonzero parent values, while UpdateProject always persists parent_project_id, so the explicit zero value bypasses the Admin requirement introduced for CVE-2026-35595. Detachment severs the recursive permission-inheritance chain and can disrupt the owner’s hierarchy and inherited collaborator access. This issue is fixed in version 2.4.0.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-55062

6 дней назад

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing parent-directory components to escape that directory. The resulting path is passed to the configured editor, which can access or modify files outside the hooks directory with the privileges of the uniget process account. This issue is fixed in version 0.27.6.

EPSS: Низкий
nvd логотип

CVE-2026-55061

6 дней назад

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go parses UNIGET_EDITOR or EDITOR with strings.Split(editor, " ") and passes every space-delimited suffix as an argument to the selected editor executable. An attacker who can influence the editor environment and cause hook editing can supply unexpected editor arguments, potentially causing unintended actions with the privileges of the uniget process account. Go os/exec does not evaluate shell operators in these arguments, so the advisory's wrapper demonstration establishes argument delivery but does not establish shell command interpretation. This issue is fixed in version 0.27.6.

EPSS: Низкий
nvd логотип

CVE-2026-55060

3 дня назад

GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the endpoint while source control child processes are running and view command-line arguments, usernames, remote material URLs, and internal material paths for materials the user cannot otherwise access. Exploitation depends on unpredictable process timing, and credentials, environment variables, and user-defined secrets remain masked or omitted. This issue is fixed in version 26.1.0.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2026-5505

5 месяцев назад

The WP-Clippy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `clippy` shortcode in all versions up to, and including, 1.0.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2026-55059

около 1 месяца назад

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12 and 3.4.13 contain a heap out-of-bounds write in Imf_4_0::SampleCountChannel::set(int r, unsigned int newNumSamples[]). The row-based sample-count setter computes the target Y coordinate with dataWindow.min.x instead of dataWindow.min.y. For a valid deep image data window where min.x != min.y, a valid row index can be translated into an invalid Y coordinate, causing writes before the allocated _numSamples buffer. The vulnerability is reachable through the public OpenEXRUtil DeepImage API and can lead to heap corruption and process crashes. This issue has been fixed in versions 3.2.10, 3.3.12 and 3.4.13.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2026-55058

2 месяца назад

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-55057

2 месяца назад

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-55056

2 месяца назад

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-55055

2 месяца назад

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-55054

2 месяца назад

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-55053

2 месяца назад

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-55052

2 месяца назад

Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-55051

2 месяца назад

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-55050

2 месяца назад

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-5504

6 месяцев назад

A padding oracle exists in wolfSSL's PKCS7 CBC decryption that could allow an attacker to recover plaintext through repeated decryption queries with modified ciphertext. In previous versions of wolfSSL the interior padding bytes are not validated.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-55049

2 месяца назад

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-55067

Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket} allows the request body project_view_id value to be mass assigned by Bucket.Update in pkg/models/kanban.go. The permission check validates that the bucket currently belongs to the URL project and view but does not validate the body selected destination view, allowing any authenticated user to relocate an attacker-owned bucket into another tenant’s Kanban view. The injected bucket retains attacker-controlled content and ownership, enabling cross-tenant defacement. This issue is fixed in version 2.4.0.

CVSS3: 5
0%
Низкий
26 дней назад
nvd логотип
CVE-2026-55066

Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}/tasks accepts a body supplied task_id but TaskBucket.CanUpdate in pkg/models/kanban_task_bucket.go authorizes only the project, view, and bucket from the URL. updateTaskBucket then calls Task.ReadOne without a separate task permission check, returns the victim task contents, and can update the task done state when the attacker chooses a done bucket. Because task identifiers are global sequential values, an authenticated user can enumerate cross-tenant tasks and modify their completion metadata through both the v1 and v2 routes that share this model. This issue is fixed in version 2.4.0.

CVSS3: 7.1
0%
Низкий
26 дней назад
nvd логотип
CVE-2026-55065

Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view identifier from another project while authorizing only against an attacker-controlled project identifier. ProjectView.CanDelete in pkg/models/project_view_permissions.go does not establish that the view belongs to the path project, and ProjectView.Delete in pkg/models/project_view.go continues after the scoped project_views delete affects no rows. Its subsequent deletes select task_buckets and task_positions only by project_view_id, allowing cross-tenant destruction of Kanban assignments and ordering while leaving the victim view and tasks intact. This issue is fixed in version 2.4.0.

CVSS3: 8.1
0%
Низкий
26 дней назад
nvd логотип
CVE-2026-55064

Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin permission on a shared child project can detach it from its parent hierarchy by submitting parent_project_id equal to 0 to POST /api/v1/projects/{project}. The Project.CanUpdate authorization check in pkg/models/project_permissions.go and UpdateProject logic in pkg/models/project.go only gate nonzero parent values, while UpdateProject always persists parent_project_id, so the explicit zero value bypasses the Admin requirement introduced for CVE-2026-35595. Detachment severs the recursive permission-inheritance chain and can disrupt the owner’s hierarchy and inherited collaborator access. This issue is fixed in version 2.4.0.

CVSS3: 4.3
0%
Низкий
26 дней назад
nvd логотип
CVE-2026-55062

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing parent-directory components to escape that directory. The resulting path is passed to the configured editor, which can access or modify files outside the hooks directory with the privileges of the uniget process account. This issue is fixed in version 0.27.6.

0%
Низкий
6 дней назад
nvd логотип
CVE-2026-55061

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go parses UNIGET_EDITOR or EDITOR with strings.Split(editor, " ") and passes every space-delimited suffix as an argument to the selected editor executable. An attacker who can influence the editor environment and cause hook editing can supply unexpected editor arguments, potentially causing unintended actions with the privileges of the uniget process account. Go os/exec does not evaluate shell operators in these arguments, so the advisory's wrapper demonstration establishes argument delivery but does not establish shell command interpretation. This issue is fixed in version 0.27.6.

0%
Низкий
6 дней назад
nvd логотип
CVE-2026-55060

GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the endpoint while source control child processes are running and view command-line arguments, usernames, remote material URLs, and internal material paths for materials the user cannot otherwise access. Exploitation depends on unpredictable process timing, and credentials, environment variables, and user-defined secrets remain masked or omitted. This issue is fixed in version 26.1.0.

CVSS3: 3.7
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-5505

The WP-Clippy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `clippy` shortcode in all versions up to, and including, 1.0.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-55059

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12 and 3.4.13 contain a heap out-of-bounds write in Imf_4_0::SampleCountChannel::set(int r, unsigned int newNumSamples[]). The row-based sample-count setter computes the target Y coordinate with dataWindow.min.x instead of dataWindow.min.y. For a valid deep image data window where min.x != min.y, a valid row index can be translated into an invalid Y coordinate, causing writes before the allocated _numSamples buffer. The vulnerability is reachable through the public OpenEXRUtil DeepImage API and can lead to heap corruption and process crashes. This issue has been fixed in versions 3.2.10, 3.3.12 and 3.4.13.

CVSS3: 6.1
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-55058

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-55057

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVSS3: 5.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-55056

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-55055

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-55054

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-55053

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-55052

Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-55051

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

CVSS3: 6.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-55050

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVSS3: 5.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5504

A padding oracle exists in wolfSSL's PKCS7 CBC decryption that could allow an attacker to recover plaintext through repeated decryption queries with modified ciphertext. In previous versions of wolfSSL the interior padding bytes are not validated.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-55049

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
2 месяца назад

Уязвимостей на страницу