Количество 396 015
Количество 396 015
CVE-2026-55011
Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.
CVE-2026-55010
Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
CVE-2026-5500
wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM authentication tag length received and has no lower bounds check. A man-in-the-middle can therefore truncate the mac field from 16 bytes to 1 byte, reducing the tag check from 2⁻¹²⁸ to 2⁻⁸.
CVE-2026-55009
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
CVE-2026-55008
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-55007
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
CVE-2026-55006
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
CVE-2026-55005
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-55004
Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.
CVE-2026-55003
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-55002
External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-55001
Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.
CVE-2026-55000
Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-54999
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.
CVE-2026-54998
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
CVE-2026-54997
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
CVE-2026-54996
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-54995
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
CVE-2026-54993
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
CVE-2026-54992
Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-55011 Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-55010 Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network. | CVSS3: 9.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-5500 wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM authentication tag length received and has no lower bounds check. A man-in-the-middle can therefore truncate the mac field from 16 bytes to 1 byte, reducing the tag check from 2⁻¹²⁸ to 2⁻⁸. | CVSS3: 5.9 | 0% Низкий | 6 месяцев назад | |
CVE-2026-55009 Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 3% Низкий | 2 месяца назад | |
CVE-2026-55008 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | CVSS3: 9.6 | 1% Низкий | 2 месяца назад | |
CVE-2026-55007 Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. | CVSS3: 8.1 | 1% Низкий | 16 дней назад | |
CVE-2026-55006 Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-55005 Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | CVSS3: 8.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-55004 Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-55003 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-55002 External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network. | CVSS3: 8.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-55001 Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-55000 Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. | CVSS3: 6.4 | 0% Низкий | 2 месяца назад | |
CVE-2026-54999 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network. | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-54998 Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | CVSS3: 8.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-54997 Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-54996 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 2 месяца назад | |
CVE-2026-54995 Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. | CVSS3: 8.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-54993 Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-54992 Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally. | CVSS3: 8.4 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу