Количество 25 045
Количество 25 045
CVE-2026-40367
Microsoft Word Remote Code Execution Vulnerability
CVE-2026-40366
Microsoft Word Remote Code Execution Vulnerability
CVE-2026-40365
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-40364
Microsoft Word Remote Code Execution Vulnerability
CVE-2026-40363
Microsoft Office Remote Code Execution Vulnerability
CVE-2026-40362
Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-40361
Microsoft Outlook and Word Remote Code Execution Vulnerability
CVE-2026-40360
Microsoft Excel Information Disclosure Vulnerability
CVE-2026-40359
Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-40358
Microsoft Office Remote Code Execution Vulnerability
CVE-2026-40357
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-40356
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.
CVE-2026-40355
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.
CVE-2026-40255
@adonisjs/http-server has an Open Redirect vulnerability
CVE-2026-40226
CVE-2026-40225
CVE-2026-40179
Prometheus: Stored XSS via metric names and label values in web UI tooltips and metrics explorer
CVE-2026-40175
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
CVE-2026-40170
ngtcp2 has a qlog transport parameter serialization stack buffer overflow
CVE-2026-40164
jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-40367 Microsoft Word Remote Code Execution Vulnerability | CVSS3: 8.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-40366 Microsoft Word Remote Code Execution Vulnerability | CVSS3: 8.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-40365 Microsoft SharePoint Server Remote Code Execution Vulnerability | CVSS3: 8.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-40364 Microsoft Word Remote Code Execution Vulnerability | CVSS3: 8.4 | 4% Низкий | 3 месяца назад | |
CVE-2026-40363 Microsoft Office Remote Code Execution Vulnerability | CVSS3: 8.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-40362 Microsoft Excel Remote Code Execution Vulnerability | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-40361 Microsoft Outlook and Word Remote Code Execution Vulnerability | CVSS3: 8.4 | 1% Низкий | 3 месяца назад | |
CVE-2026-40360 Microsoft Excel Information Disclosure Vulnerability | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-40359 Microsoft Excel Remote Code Execution Vulnerability | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-40358 Microsoft Office Remote Code Execution Vulnerability | CVSS3: 8.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-40357 Microsoft SharePoint Server Remote Code Execution Vulnerability | CVSS3: 8.8 | 2% Низкий | 3 месяца назад | |
CVE-2026-40356 In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message. | CVSS3: 5.9 | 1% Низкий | 3 месяца назад | |
CVE-2026-40355 In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message. | CVSS3: 5.9 | 1% Низкий | 2 месяца назад | |
CVE-2026-40255 @adonisjs/http-server has an Open Redirect vulnerability | 0% Низкий | 4 месяца назад | ||
0% Низкий | 4 месяца назад | |||
0% Низкий | 3 месяца назад | |||
CVE-2026-40179 Prometheus: Stored XSS via metric names and label values in web UI tooltips and metrics explorer | 0% Низкий | 4 месяца назад | ||
CVE-2026-40175 Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain | 2% Низкий | 4 месяца назад | ||
CVE-2026-40170 ngtcp2 has a qlog transport parameter serialization stack buffer overflow | 1% Низкий | 3 месяца назад | ||
CVE-2026-40164 jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed | CVSS3: 7.5 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу