Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 75 967

Количество 75 967

ubuntu логотип

CVE-2026-76887

7 дней назад

Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2026-76886

7 дней назад

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2026-76885

7 дней назад

Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2026-76884

7 дней назад

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2026-76883

7 дней назад

Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2026-76882

7 дней назад

Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2026-76881

7 дней назад

CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2026-76880

7 дней назад

RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-76879

7 дней назад

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-76878

7 дней назад

In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked p...

EPSS: Низкий
ubuntu логотип

CVE-2026-7666

3 месяца назад

An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake when `fail_silently=True`, which allows on-path network attackers to read email content via cleartext interception. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Kasper Dupont for reporting this issue.

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2026-76641

7 дней назад

(Expat through 2.8.3 contains an out-of-bounds read vulnerability that ...)

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-76235

8 дней назад

(A memory leak flaw was found in cockpit-ws. The login page handler lea ...)

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-76222

8 дней назад

(GitPython before 3.1.58 fails to validate submodule names from .gitmod ...)

CVSS3: 8.2
EPSS: Низкий
ubuntu логотип

CVE-2026-76221

8 дней назад

(GitPython before 3.1.58 contains a config-name injection vulnerability ...)

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2026-76220

8 дней назад

(GitPython before 3.1.58 contains a command execution vulnerability in ...)

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2026-76219

8 дней назад

(GitPython versions before 3.1.58 contain an arbitrary file overwrite v ...)

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2026-76218

8 дней назад

(GitPython before 3.1.58 contains a remote code execution vulnerability ...)

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-76217

8 дней назад

(GitPython versions before 3.1.58 fail to validate options passed to gi ...)

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-76047

8 дней назад

Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-76887

Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 3.1
0%
Низкий
7 дней назад
ubuntu логотип
CVE-2026-76886

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 8.1
0%
Низкий
7 дней назад
ubuntu логотип
CVE-2026-76885

Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 3.1
0%
Низкий
7 дней назад
ubuntu логотип
CVE-2026-76884

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 3.1
0%
Низкий
7 дней назад
ubuntu логотип
CVE-2026-76883

Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 4.7
0%
Низкий
7 дней назад
ubuntu логотип
CVE-2026-76882

Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 4.7
0%
Низкий
7 дней назад
ubuntu логотип
CVE-2026-76881

CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 4.7
0%
Низкий
7 дней назад
ubuntu логотип
CVE-2026-76880

RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 7.5
0%
Низкий
7 дней назад
ubuntu логотип
CVE-2026-76879

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 7.5
0%
Низкий
7 дней назад
ubuntu логотип
CVE-2026-76878

In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked p...

0%
Низкий
7 дней назад
ubuntu логотип
CVE-2026-7666

An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake when `fail_silently=True`, which allows on-path network attackers to read email content via cleartext interception. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Kasper Dupont for reporting this issue.

CVSS3: 3.1
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-76641

(Expat through 2.8.3 contains an out-of-bounds read vulnerability that ...)

CVSS3: 7.5
0%
Низкий
7 дней назад
ubuntu логотип
CVE-2026-76235

(A memory leak flaw was found in cockpit-ws. The login page handler lea ...)

CVSS3: 7.5
0%
Низкий
8 дней назад
ubuntu логотип
CVE-2026-76222

(GitPython before 3.1.58 fails to validate submodule names from .gitmod ...)

CVSS3: 8.2
0%
Низкий
8 дней назад
ubuntu логотип
CVE-2026-76221

(GitPython before 3.1.58 contains a config-name injection vulnerability ...)

CVSS3: 8.8
0%
Низкий
8 дней назад
ubuntu логотип
CVE-2026-76220

(GitPython before 3.1.58 contains a command execution vulnerability in ...)

CVSS3: 8.8
0%
Низкий
8 дней назад
ubuntu логотип
CVE-2026-76219

(GitPython versions before 3.1.58 contain an arbitrary file overwrite v ...)

CVSS3: 8.1
0%
Низкий
8 дней назад
ubuntu логотип
CVE-2026-76218

(GitPython before 3.1.58 contains a remote code execution vulnerability ...)

CVSS3: 7.5
0%
Низкий
8 дней назад
ubuntu логотип
CVE-2026-76217

(GitPython versions before 3.1.58 fail to validate options passed to gi ...)

CVSS3: 6.5
0%
Низкий
8 дней назад
ubuntu логотип
CVE-2026-76047

Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
8 дней назад

Уязвимостей на страницу