Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25 045

Количество 25 045

msrc логотип

CVE-2026-34873

3 месяца назад

An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.

EPSS: Низкий
msrc логотип

CVE-2026-34872

3 месяца назад

An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle).

EPSS: Низкий
msrc логотип

CVE-2026-34871

3 месяца назад

An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG).

EPSS: Низкий
msrc логотип

CVE-2026-3479

4 месяца назад

pkgutil.get_data() does not enforce documented restrictions

EPSS: Низкий
msrc логотип

CVE-2026-34757

4 месяца назад

LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure

CVSS3: 5.1
EPSS: Низкий
msrc логотип

CVE-2026-34743

4 месяца назад

XZ Utils: Buffer overflow in lzma_index_append()

EPSS: Низкий
msrc логотип

CVE-2026-34714

4 месяца назад

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

CVSS3: 8.5
EPSS: Низкий
msrc логотип

CVE-2026-34601

4 месяца назад

xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion

EPSS: Низкий
msrc логотип

CVE-2026-34591

3 месяца назад

Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write

EPSS: Низкий
msrc логотип

CVE-2026-34481

4 месяца назад

Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout

EPSS: Низкий
msrc логотип

CVE-2026-34480

4 месяца назад

Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters

EPSS: Низкий
msrc логотип

CVE-2026-34479

4 месяца назад

Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters

EPSS: Низкий
msrc логотип

CVE-2026-34477

4 месяца назад

Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass

EPSS: Низкий
msrc логотип

CVE-2026-34446

4 месяца назад

ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load

CVSS3: 4.7
EPSS: Низкий
msrc логотип

CVE-2026-34445

4 месяца назад

ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.

CVSS3: 8.6
EPSS: Низкий
msrc логотип

CVE-2026-34356

около 2 месяцев назад

Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow

EPSS: Низкий
msrc логотип

CVE-2026-34355

около 2 месяцев назад

Apache HTTP Server: mod_proxy_html buffer overflow

EPSS: Низкий
msrc логотип

CVE-2026-34353

4 месяца назад

In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2026-34351

3 месяца назад

Windows TCP/IP Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2026-34350

3 месяца назад

Windows Storport Miniport Driver Denial of Service Vulnerability

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2026-34873

An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.

0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-34872

An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle).

0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-34871

An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG).

0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-3479

pkgutil.get_data() does not enforce documented restrictions

0%
Низкий
4 месяца назад
msrc логотип
CVE-2026-34757

LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure

CVSS3: 5.1
0%
Низкий
4 месяца назад
msrc логотип
CVE-2026-34743

XZ Utils: Buffer overflow in lzma_index_append()

0%
Низкий
4 месяца назад
msrc логотип
CVE-2026-34714

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

CVSS3: 8.5
1%
Низкий
4 месяца назад
msrc логотип
CVE-2026-34601

xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion

0%
Низкий
4 месяца назад
msrc логотип
CVE-2026-34591

Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write

0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-34481

Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout

1%
Низкий
4 месяца назад
msrc логотип
CVE-2026-34480

Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters

1%
Низкий
4 месяца назад
msrc логотип
CVE-2026-34479

Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters

1%
Низкий
4 месяца назад
msrc логотип
CVE-2026-34477

Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass

0%
Низкий
4 месяца назад
msrc логотип
CVE-2026-34446

ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load

CVSS3: 4.7
0%
Низкий
4 месяца назад
msrc логотип
CVE-2026-34445

ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.

CVSS3: 8.6
0%
Низкий
4 месяца назад
msrc логотип
CVE-2026-34356

Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow

1%
Низкий
около 2 месяцев назад
msrc логотип
CVE-2026-34355

Apache HTTP Server: mod_proxy_html buffer overflow

1%
Низкий
около 2 месяцев назад
msrc логотип
CVE-2026-34353

In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.

CVSS3: 5.9
0%
Низкий
4 месяца назад
msrc логотип
CVE-2026-34351

Windows TCP/IP Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-34350

Windows Storport Miniport Driver Denial of Service Vulnerability

CVSS3: 6.5
1%
Низкий
3 месяца назад

Уязвимостей на страницу