Количество 25 045
Количество 25 045
CVE-2026-41526
In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applications relying on this method in a security-critical path to handle user input are affected and could be exploited. In particular, because sendInput() sends a string to a terminal, a control character such as \x01 can be used during injection.
CVE-2026-41445
KissFFT Integer Overflow Heap Buffer Overflow via kiss_fftndr_alloc()
CVE-2026-41411
Vim: Command injection via backtick expansion in tag filenames
CVE-2026-41401
libyang - Heap Use-After-Free Write in XML Metadata Parsing
CVE-2026-41305
PostCSS has XSS via Unescaped </style> in its CSS Stringify Output
CVE-2026-41292
Long list of incoming EDNS options degrades performance
CVE-2026-41257
jq: Signed-int overflow in `stack_reallocate` (jq VM stack)
CVE-2026-41256
jq: Embedded NUL truncates top-level jq programs loaded with -f
CVE-2026-41254
CVE-2026-41205
Mako: Path traversal via double-slash URI prefix in TemplateLookup
CVE-2026-41184
ServiceAccount token disclosure via install-cni container logs
CVE-2026-41140
Poetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4
CVE-2026-4111
Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive
CVE-2026-41109
GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-41108
Windows DNS Client Elevation of Privilege Vulnerability
CVE-2026-41107
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-41106
Microsoft 365 Copilot Elevation of Privilege Vulnerability
CVE-2026-41105
Azure Monitor Action Group Notification System Elevation of Privilege Vulnerability
CVE-2026-41104
Microsoft Planetary Computer Pro Information Disclosure Vulnerability
CVE-2026-41103
Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-41526 In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applications relying on this method in a security-critical path to handle user input are affected and could be exploited. In particular, because sendInput() sends a string to a terminal, a control character such as \x01 can be used during injection. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-41445 KissFFT Integer Overflow Heap Buffer Overflow via kiss_fftndr_alloc() | 0% Низкий | 4 месяца назад | ||
CVE-2026-41411 Vim: Command injection via backtick expansion in tag filenames | CVSS3: 6.6 | 1% Низкий | 3 месяца назад | |
CVE-2026-41401 libyang - Heap Use-After-Free Write in XML Metadata Parsing | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-41305 PostCSS has XSS via Unescaped </style> in its CSS Stringify Output | 0% Низкий | 3 месяца назад | ||
CVE-2026-41292 Long list of incoming EDNS options degrades performance | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-41257 jq: Signed-int overflow in `stack_reallocate` (jq VM stack) | 0% Низкий | 3 месяца назад | ||
CVE-2026-41256 jq: Embedded NUL truncates top-level jq programs loaded with -f | CVSS3: 5.5 | 0% Низкий | 3 месяца назад | |
CVSS3: 4 | 0% Низкий | 3 месяца назад | ||
CVE-2026-41205 Mako: Path traversal via double-slash URI prefix in TemplateLookup | 0% Низкий | 3 месяца назад | ||
CVE-2026-41184 ServiceAccount token disclosure via install-cni container logs | 1% Низкий | 2 месяца назад | ||
CVE-2026-41140 Poetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4 | 0% Низкий | 3 месяца назад | ||
CVE-2026-4111 Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
CVE-2026-41109 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability | CVSS3: 8.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-41108 Windows DNS Client Elevation of Privilege Vulnerability | CVSS3: 7 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-41107 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | CVSS3: 7.4 | 1% Низкий | 3 месяца назад | |
CVE-2026-41106 Microsoft 365 Copilot Elevation of Privilege Vulnerability | 1% Низкий | около 1 месяца назад | ||
CVE-2026-41105 Azure Monitor Action Group Notification System Elevation of Privilege Vulnerability | 1% Низкий | 3 месяца назад | ||
CVE-2026-41104 Microsoft Planetary Computer Pro Information Disclosure Vulnerability | 1% Низкий | 3 месяца назад | ||
CVE-2026-41103 Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability | CVSS3: 9.1 | 5% Низкий | 3 месяца назад |
Уязвимостей на страницу