Количество 25 065
Количество 25 065
CVE-2026-33822
Microsoft Word Information Disclosure Vulnerability
CVE-2026-33821
Microsoft Dynamics 365 Customer Insights Elevation of Privilege Vulnerability
CVE-2026-3381
Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib
CVE-2026-33819
Microsoft Bing Remote Code Execution Vulnerability
CVE-2026-33814
Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
CVE-2026-33811
Crash when handling long CNAME response in net
CVE-2026-33810
Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509
CVE-2026-33750
brace-expansion: Zero-step sequence causes process hang and memory exhaustion
CVE-2026-33672
Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
CVE-2026-33671
Picomatch has a ReDoS vulnerability via extglob quantifiers
CVE-2026-33636
LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64
CVE-2026-33555
CVE-2026-33554
ipmi-oem in FreeIPMI before 1.16.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Three subcommands were found to have exploitable buffer overflows on response messages. They are: "ipmi-oem dell get-last-post-code - get the last POST code and string describing the error on some Dell servers," "ipmi-oem supermicro extra-firmware-info - get extra firmware info on Supermic
CVE-2026-33542
Incus does not verify combined fingerprint when downloading images from simplestreams servers
CVE-2026-33526
Squid vulnerable to Denial of Service in ICP Request handling
CVE-2026-33523
Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line
CVE-2026-33515
Squid has issues in ICP message handling
CVE-2026-33489
CoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison
CVE-2026-33416
LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE`
CVE-2026-33413
etcd: Authorization bypasses in multiple APIs
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-33822 Microsoft Word Information Disclosure Vulnerability | CVSS3: 6.1 | 0% Низкий | 4 месяца назад | |
CVE-2026-33821 Microsoft Dynamics 365 Customer Insights Elevation of Privilege Vulnerability | 1% Низкий | 3 месяца назад | ||
CVE-2026-3381 Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib | CVSS3: 9.8 | 1% Низкий | 5 месяцев назад | |
CVE-2026-33819 Microsoft Bing Remote Code Execution Vulnerability | 1% Низкий | 4 месяца назад | ||
CVE-2026-33814 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-33811 Crash when handling long CNAME response in net | 1% Низкий | 3 месяца назад | ||
CVE-2026-33810 Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509 | CVSS3: 5.9 | 0% Низкий | 4 месяца назад | |
CVE-2026-33750 brace-expansion: Zero-step sequence causes process hang and memory exhaustion | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-33672 Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
CVE-2026-33671 Picomatch has a ReDoS vulnerability via extglob quantifiers | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-33636 LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64 | CVSS3: 7.6 | 1% Низкий | 4 месяца назад | |
CVSS3: 4 | 0% Низкий | 4 месяца назад | ||
CVE-2026-33554 ipmi-oem in FreeIPMI before 1.16.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Three subcommands were found to have exploitable buffer overflows on response messages. They are: "ipmi-oem dell get-last-post-code - get the last POST code and string describing the error on some Dell servers," "ipmi-oem supermicro extra-firmware-info - get extra firmware info on Supermic | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-33542 Incus does not verify combined fingerprint when downloading images from simplestreams servers | 0% Низкий | 4 месяца назад | ||
CVE-2026-33526 Squid vulnerable to Denial of Service in ICP Request handling | CVSS3: 7.5 | 9% Низкий | 4 месяца назад | |
CVE-2026-33523 Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-33515 Squid has issues in ICP message handling | CVSS3: 5.3 | 1% Низкий | 4 месяца назад | |
CVE-2026-33489 CoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison | 0% Низкий | 3 месяца назад | ||
CVE-2026-33416 LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE` | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-33413 etcd: Authorization bypasses in multiple APIs | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу