Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 209

Количество 331 209

nvd логотип

CVE-2026-24353

15 дней назад

Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through <= 4.4.9.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-24348

11 дней назад

Multiple cross-site scripting vulnerabilities in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to execute arbitrary JavaScript code in the browser of other Admin UI users.

EPSS: Низкий
nvd логотип

CVE-2026-24347

11 дней назад

Improper input validation in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to manipulate files in the /tmp directory

EPSS: Низкий
nvd логотип

CVE-2026-24346

11 дней назад

Use of well-known default credentials in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to access protected areas in the web application

EPSS: Низкий
nvd логотип

CVE-2026-24345

11 дней назад

Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization checks and gain full access to the admin UI

EPSS: Низкий
nvd логотип

CVE-2026-24344

11 дней назад

Multiple Buffer Overflows in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to cause a program crash and potential remote code execution

EPSS: Низкий
nvd логотип

CVE-2026-24342

15 дней назад

Rejected reason: Not used

EPSS: Низкий
nvd логотип

CVE-2026-24341

15 дней назад

Rejected reason: Not used

EPSS: Низкий
nvd логотип

CVE-2026-24340

15 дней назад

Rejected reason: Not used

EPSS: Низкий
nvd логотип

CVE-2026-24339

15 дней назад

Rejected reason: Not used

EPSS: Низкий
nvd логотип

CVE-2026-24338

15 дней назад

Rejected reason: Not used

EPSS: Низкий
nvd логотип

CVE-2026-24337

15 дней назад

Rejected reason: Not used

EPSS: Низкий
nvd логотип

CVE-2026-24336

15 дней назад

Rejected reason: Not used

EPSS: Низкий
nvd логотип

CVE-2026-24335

15 дней назад

Rejected reason: Not used

EPSS: Низкий
nvd логотип

CVE-2026-24334

15 дней назад

Rejected reason: Not used

EPSS: Низкий
nvd логотип

CVE-2026-24332

16 дней назад

Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the response to a WebSocket API request includes the user in the presences array (with "status": "offline"), whereas offline users are omitted from the presences array. This is arguably inconsistent with the UI description of Invisible as "You will appear offline."

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-24307

15 дней назад

Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-24306

15 дней назад

Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-24305

15 дней назад

Azure Entra ID Elevation of Privilege Vulnerability

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-24304

15 дней назад

Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.

CVSS3: 9.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-24353

Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through <= 4.4.9.

CVSS3: 8.1
0%
Низкий
15 дней назад
nvd логотип
CVE-2026-24348

Multiple cross-site scripting vulnerabilities in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to execute arbitrary JavaScript code in the browser of other Admin UI users.

0%
Низкий
11 дней назад
nvd логотип
CVE-2026-24347

Improper input validation in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to manipulate files in the /tmp directory

0%
Низкий
11 дней назад
nvd логотип
CVE-2026-24346

Use of well-known default credentials in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to access protected areas in the web application

0%
Низкий
11 дней назад
nvd логотип
CVE-2026-24345

Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization checks and gain full access to the admin UI

0%
Низкий
11 дней назад
nvd логотип
CVE-2026-24344

Multiple Buffer Overflows in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to cause a program crash and potential remote code execution

0%
Низкий
11 дней назад
nvd логотип
CVE-2026-24342

Rejected reason: Not used

15 дней назад
nvd логотип
CVE-2026-24341

Rejected reason: Not used

15 дней назад
nvd логотип
CVE-2026-24340

Rejected reason: Not used

15 дней назад
nvd логотип
CVE-2026-24339

Rejected reason: Not used

15 дней назад
nvd логотип
CVE-2026-24338

Rejected reason: Not used

15 дней назад
nvd логотип
CVE-2026-24337

Rejected reason: Not used

15 дней назад
nvd логотип
CVE-2026-24336

Rejected reason: Not used

15 дней назад
nvd логотип
CVE-2026-24335

Rejected reason: Not used

15 дней назад
nvd логотип
CVE-2026-24334

Rejected reason: Not used

15 дней назад
nvd логотип
CVE-2026-24332

Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the response to a WebSocket API request includes the user in the presences array (with "status": "offline"), whereas offline users are omitted from the presences array. This is arguably inconsistent with the UI description of Invisible as "You will appear offline."

CVSS3: 4.3
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-24307

Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVSS3: 9.3
0%
Низкий
15 дней назад
nvd логотип
CVE-2026-24306

Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 9.8
0%
Низкий
15 дней назад
nvd логотип
CVE-2026-24305

Azure Entra ID Elevation of Privilege Vulnerability

CVSS3: 9.3
0%
Низкий
15 дней назад
nvd логотип
CVE-2026-24304

Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.

CVSS3: 9.9
0%
Низкий
15 дней назад

Уязвимостей на страницу