Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 083

Количество 374 083

nvd логотип

CVE-2026-65435

12 дней назад

Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65434

12 дней назад

Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65433

12 дней назад

Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65432

2 дня назад

Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <xsd:import> referenced from that top-level WSDL is handed off to WSDL4J, which does not disable DOCTYPE declarations or external entities. As a result, the protections applied to the top-level document do not extend to imported documents, leaving imported WSDL/XSD content vulnerable to XML External Entity (XXE) attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-65431

16 дней назад

Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-65430

16 дней назад

Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-6542

3 месяца назад

IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build data belonging to other users, and to delete persisted vertex build data for another user's flow.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65423

9 дней назад

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-65421

9 дней назад

The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-6541

26 дней назад

Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or update request with a foreign metric ID. Mattermost Advisory ID: MMSA-2026-00653

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-6540

9 дней назад

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes are not correctly evaluated by Prefix path rules. Dikastes authorizes the request under the permitted prefix while the downstream workload or a fronting proxy normalizes the path and serves the restricted endpoint. An attacker with network access and no special RBAC can potentially reach HTTP endpoints the policy was intended to restrict.

EPSS: Низкий
nvd логотип

CVE-2026-65400

2 дня назад

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-6539

3 месяца назад

Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by crafting a malicious nativeLang.xml language pack file. Attackers can distribute a poisoned language pack through community channels that triggers format string interpretation when a user performs search operations, leading to access violations and potential leakage of stack or register contents.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2026-6538

3 месяца назад

BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-6537

3 месяца назад

ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-6536

3 месяца назад

DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-6535

3 месяца назад

Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-6534

3 месяца назад

USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-6533

3 месяца назад

Dissection engine LZ77 decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-6532

3 месяца назад

Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-65435

Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.

CVSS3: 6.5
0%
Низкий
12 дней назад
nvd логотип
CVE-2026-65434

Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.

CVSS3: 6.5
0%
Низкий
12 дней назад
nvd логотип
CVE-2026-65433

Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions.

CVSS3: 6.5
0%
Низкий
12 дней назад
nvd логотип
CVE-2026-65432

Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <xsd:import> referenced from that top-level WSDL is handed off to WSDL4J, which does not disable DOCTYPE declarations or external entities. As a result, the protections applied to the top-level document do not extend to imported documents, leaving imported WSDL/XSD content vulnerable to XML External Entity (XXE) attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

CVSS3: 7.5
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-65431

Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.

CVSS3: 9.8
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65430

Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.

CVSS3: 7.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-6542

IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build data belonging to other users, and to delete persisted vertex build data for another user's flow.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-65423

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write.

CVSS3: 8.8
1%
Низкий
9 дней назад
nvd логотип
CVE-2026-65421

The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition.

CVSS3: 6.5
0%
Низкий
9 дней назад
nvd логотип
CVE-2026-6541

Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or update request with a foreign metric ID. Mattermost Advisory ID: MMSA-2026-00653

CVSS3: 4.3
0%
Низкий
26 дней назад
nvd логотип
CVE-2026-6540

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes are not correctly evaluated by Prefix path rules. Dikastes authorizes the request under the permitted prefix while the downstream workload or a fronting proxy normalizes the path and serves the restricted endpoint. An attacker with network access and no special RBAC can potentially reach HTTP endpoints the policy was intended to restrict.

0%
Низкий
9 дней назад
nvd логотип
CVE-2026-65400

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

CVSS3: 7.1
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-6539

Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by crafting a malicious nativeLang.xml language pack file. Attackers can distribute a poisoned language pack through community channels that triggers format string interpretation when a user performs search operations, leading to access violations and potential leakage of stack or register contents.

CVSS3: 4.4
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-6538

BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-6537

ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-6536

DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4

CVSS3: 5.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-6535

Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-6534

USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-6533

Dissection engine LZ77 decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-6532

Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу