Количество 25 355
Количество 25 355
CVE-2026-27784
NGINX ngx_http_mp4_module vulnerability
CVE-2026-27654
NGINX ngx_http_dav_module vulnerability
CVE-2026-27651
NGINX ngx_mail_auth_http_module vulnerability
CVE-2026-27623
Valkey has Pre-Authentication DOS from malformed RESP request
CVE-2026-27601
Underscore.js has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack
CVE-2026-27571
nats-server websockets are vulnerable to pre-auth memory DoS
CVE-2026-27459
pyOpenSSL DTLS cookie callback buffer overflow
CVE-2026-27456
util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup
CVE-2026-27448
pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback
CVE-2026-27447
OpenPrinting CUPS: Authorization bypass via case-insensitive group-member lookup
CVE-2026-2739
This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely.
CVE-2026-27211
Cloud Hypervisor: Host File Exfiltration via QCOW Backing File Abuse
CVE-2026-27199
Werkzeug safe_join() allows Windows special device names
CVE-2026-27171
zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
CVE-2026-27145
Inefficient candidate hostname parsing in crypto/x509
CVE-2026-27144
Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile
CVE-2026-27143
Missing bound checks can lead to memory corruption in safe Go in cmd/compile
CVE-2026-27142
URLs in meta content attribute actions are not escaped in html/template
CVE-2026-27141
Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net
CVE-2026-27140
Code execution vulnerability in SWIG code generation in cmd/go
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-27784 NGINX ngx_http_mp4_module vulnerability | CVSS3: 7.8 | 1% Низкий | 4 месяца назад | |
CVE-2026-27654 NGINX ngx_http_dav_module vulnerability | CVSS3: 8.2 | 22% Средний | 4 месяца назад | |
CVE-2026-27651 NGINX ngx_mail_auth_http_module vulnerability | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-27623 Valkey has Pre-Authentication DOS from malformed RESP request | 0% Низкий | 5 месяцев назад | ||
CVE-2026-27601 Underscore.js has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack | 1% Низкий | 5 месяцев назад | ||
CVE-2026-27571 nats-server websockets are vulnerable to pre-auth memory DoS | CVSS3: 5.9 | 0% Низкий | 5 месяцев назад | |
CVE-2026-27459 pyOpenSSL DTLS cookie callback buffer overflow | 1% Низкий | 5 месяцев назад | ||
CVE-2026-27456 util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup | CVSS3: 4.7 | 0% Низкий | 4 месяца назад | |
CVE-2026-27448 pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback | 0% Низкий | 5 месяцев назад | ||
CVE-2026-27447 OpenPrinting CUPS: Authorization bypass via case-insensitive group-member lookup | CVSS3: 4.8 | 0% Низкий | 4 месяца назад | |
CVE-2026-2739 This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely. | 0% Низкий | 5 месяцев назад | ||
CVE-2026-27211 Cloud Hypervisor: Host File Exfiltration via QCOW Backing File Abuse | CVSS3: 10 | 1% Низкий | 5 месяцев назад | |
CVE-2026-27199 Werkzeug safe_join() allows Windows special device names | 1% Низкий | 5 месяцев назад | ||
CVE-2026-27171 zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition. | CVSS3: 2.9 | 0% Низкий | 6 месяцев назад | |
CVE-2026-27145 Inefficient candidate hostname parsing in crypto/x509 | 1% Низкий | 2 месяца назад | ||
CVE-2026-27144 Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile | 0% Низкий | 4 месяца назад | ||
CVE-2026-27143 Missing bound checks can lead to memory corruption in safe Go in cmd/compile | 1% Низкий | 4 месяца назад | ||
CVE-2026-27142 URLs in meta content attribute actions are not escaped in html/template | 0% Низкий | 5 месяцев назад | ||
CVE-2026-27141 Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
CVE-2026-27140 Code execution vulnerability in SWIG code generation in cmd/go | 1% Низкий | 4 месяца назад |
Уязвимостей на страницу