Количество 25 045
Количество 25 045
CVE-2026-42533
NGINX Map directive and Regex matching vulnerability
CVE-2026-42508
Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts
CVE-2026-42507
Arbitrary inputs are included in errors without any escaping in net/textproto
CVE-2026-42506
Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html
CVE-2026-42505
Invoking Encrypted Client Hello privacy leak in crypto/tls
CVE-2026-42504
Quadratic complexity in WordDecoder.DecodeHeader in mime
CVE-2026-42502
Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html
CVE-2026-42501
Malicious module proxy can bypass checksum database in cmd/go
CVE-2026-42499
Quadratic string concatenation in consumePhrase in net/mail
CVE-2026-42497
Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory
CVE-2026-42496
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory
CVE-2026-42304
Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
CVE-2026-42258
net-imap: Command Injection via unvalidated Symbol inputs
CVE-2026-42257
net-imap: Command Injection via "raw" arguments to multiple commands
CVE-2026-42256
net-imap: Denial of service via high iteration count for `SCRAM-*` authentication
CVE-2026-42250
Off-by-One Leading to Out-of-Bounds Write in bzip2
CVE-2026-4224
Stack overflow parsing XML with deeply nested DTD content models
CVE-2026-42246
net-imap vulnerable to STARTTLS stripping via invalid response timing
CVE-2026-42154
Prometheus: remote read endpoint allows denial of service via crafted snappy payload
CVE-2026-42151
Prometheus Azure AD remote write OAuth client secret exposed via config API
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-42533 NGINX Map directive and Regex matching vulnerability | CVSS3: 8.1 | 4% Низкий | 18 дней назад | |
CVE-2026-42508 Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts | CVSS3: 9.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-42507 Arbitrary inputs are included in errors without any escaping in net/textproto | CVSS3: 5.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-42506 Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | CVSS3: 6.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-42505 Invoking Encrypted Client Hello privacy leak in crypto/tls | 0% Низкий | 22 дня назад | ||
CVE-2026-42504 Quadratic complexity in WordDecoder.DecodeHeader in mime | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-42502 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | CVSS3: 6.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-42501 Malicious module proxy can bypass checksum database in cmd/go | 0% Низкий | 3 месяца назад | ||
CVE-2026-42499 Quadratic string concatenation in consumePhrase in net/mail | 1% Низкий | 3 месяца назад | ||
CVE-2026-42497 Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory | 0% Низкий | 2 месяца назад | ||
CVE-2026-42496 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory | CVSS3: 9.1 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-42304 Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-42258 net-imap: Command Injection via unvalidated Symbol inputs | 1% Низкий | 3 месяца назад | ||
CVE-2026-42257 net-imap: Command Injection via "raw" arguments to multiple commands | 0% Низкий | 3 месяца назад | ||
CVE-2026-42256 net-imap: Denial of service via high iteration count for `SCRAM-*` authentication | 0% Низкий | 3 месяца назад | ||
CVE-2026-42250 Off-by-One Leading to Out-of-Bounds Write in bzip2 | 0% Низкий | 2 месяца назад | ||
CVE-2026-4224 Stack overflow parsing XML with deeply nested DTD content models | 1% Низкий | 5 месяцев назад | ||
CVE-2026-42246 net-imap vulnerable to STARTTLS stripping via invalid response timing | 0% Низкий | 3 месяца назад | ||
CVE-2026-42154 Prometheus: remote read endpoint allows denial of service via crafted snappy payload | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-42151 Prometheus Azure AD remote write OAuth client secret exposed via config API | CVSS3: 7.5 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу