Количество 376 173
Количество 376 173
CVE-2026-62872
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
CVE-2026-62871
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-62870
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
CVE-2026-62869
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.
CVE-2026-62857
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1, 2.2, and 2.3 maintenance lines, getNodeInfo() follows an attacker-controlled links[].href value from /.well-known/nodeinfo without scheme, redirect, or private-address validation, allowing requests to loopback, link-local, cloud metadata, and private-network services and returning their response bodies. This issue is fixed in versions 1.9.13, 1.10.12, 2.0.22, 2.1.18, 2.2.7, and 2.3.2.
CVE-2026-6284
An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no password input limiters makes brute force password enumeration possible.
CVE-2026-62845
Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivers build DDL statements by interpolating the user-supplied DataStoreUsername/DataStoreSchema directly into SQL via fmt.Sprintf, without escaping identifiers. These fields have no format validation, so a value containing a quote character breaks out of the quoted identifier — SQL injection executed over Kamaji's root connection to the shared datastore. etcd driver is not affected.This issue is fixed in version 26.7.4-edge.
CVE-2026-62843
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses strings.ReplaceAll(nameInArchive, "\", "/"), which turns a POSIX filename such as ..\..\evil.sh into the archive entry ../../evil.sh, allowing a user with upload permission to plant a backslash-named file that escapes the extraction directory when another user downloads and extracts the generated zip or tar archive. This issue is fixed in version 2.63.17.
CVE-2026-62842
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-6283
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from v.4.8.2.23 before v.4.8.3.1.
CVE-2026-62839
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-62837
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
CVE-2026-62836
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62835
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
CVE-2026-62832
Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62830
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
CVE-2026-6282
A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access files belonging to other users on the same device.
CVE-2026-62829
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-62828
Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network.
CVE-2026-62827
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-62872 Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. | CVSS3: 8.8 | 1% Низкий | 2 дня назад | |
CVE-2026-62871 Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 2 дня назад | |
CVE-2026-62870 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. | CVSS3: 8.8 | 1% Низкий | 10 дней назад | |
CVE-2026-62869 Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network. | CVSS3: 8.8 | 0% Низкий | 2 дня назад | |
CVE-2026-62857 Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1, 2.2, and 2.3 maintenance lines, getNodeInfo() follows an attacker-controlled links[].href value from /.well-known/nodeinfo without scheme, redirect, or private-address validation, allowing requests to loopback, link-local, cloud metadata, and private-network services and returning their response bodies. This issue is fixed in versions 1.9.13, 1.10.12, 2.0.22, 2.1.18, 2.2.7, and 2.3.2. | 0% Низкий | 7 дней назад | ||
CVE-2026-6284 An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no password input limiters makes brute force password enumeration possible. | CVSS3: 9.1 | 0% Низкий | 4 месяца назад | |
CVE-2026-62845 Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivers build DDL statements by interpolating the user-supplied DataStoreUsername/DataStoreSchema directly into SQL via fmt.Sprintf, without escaping identifiers. These fields have no format validation, so a value containing a quote character breaks out of the quoted identifier — SQL injection executed over Kamaji's root connection to the shared datastore. etcd driver is not affected.This issue is fixed in version 26.7.4-edge. | CVSS3: 4.7 | 0% Низкий | 14 дней назад | |
CVE-2026-62843 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses strings.ReplaceAll(nameInArchive, "\", "/"), which turns a POSIX filename such as ..\..\evil.sh into the archive entry ../../evil.sh, allowing a user with upload permission to plant a backslash-named file that escapes the extraction directory when another user downloads and extracts the generated zip or tar archive. This issue is fixed in version 2.63.17. | CVSS3: 6.8 | 0% Низкий | 29 дней назад | |
CVE-2026-62842 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 2 дня назад | |
CVE-2026-6283 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from v.4.8.2.23 before v.4.8.3.1. | CVSS3: 5.4 | 0% Низкий | около 1 месяца назад | |
CVE-2026-62839 Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | CVSS3: 6.5 | 1% Низкий | 2 дня назад | |
CVE-2026-62837 Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | CVSS3: 6.5 | 1% Низкий | 2 дня назад | |
CVE-2026-62836 Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network. | CVSS3: 8.7 | 0% Низкий | 7 дней назад | |
CVE-2026-62835 Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. | CVSS3: 9.3 | 1% Низкий | 20 дней назад | |
CVE-2026-62832 Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 2% Низкий | 2 дня назад | |
CVE-2026-62830 Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. | CVSS3: 9.9 | 0% Низкий | 7 дней назад | |
CVE-2026-6282 A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access files belonging to other users on the same device. | CVSS3: 8.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-62829 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | CVSS3: 4.6 | 0% Низкий | 2 дня назад | |
CVE-2026-62828 Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network. | CVSS3: 5.4 | 0% Низкий | 16 дней назад | |
CVE-2026-62827 Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | CVSS3: 8.8 | 1% Низкий | 2 дня назад |
Уязвимостей на страницу