Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 173

Количество 376 173

nvd логотип

CVE-2026-62826

28 дней назад

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVSS3: 4.6
EPSS: Низкий
nvd логотип

CVE-2026-62825

21 день назад

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
EPSS: Низкий
nvd логотип

CVE-2026-62824

2 дня назад

Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-62823

2 дня назад

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-62822

2 дня назад

Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-62820

2 дня назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-6281

3 месяца назад

A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-62819

2 дня назад

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-62818

2 дня назад

Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-62817

2 дня назад

Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-62816

2 дня назад

Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-62815

2 дня назад

Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-62814

2 дня назад

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-62812

2 дня назад

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62811

2 дня назад

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-6280

около 1 месяца назад

Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Nomysem: through 08072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-62807

2 дня назад

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62803

2 дня назад

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62800

2 дня назад

Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-6279

3 месяца назад

The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2. This is due to the `wp_conditional_tags` case in `Fusion_Builder_Conditional_Render_Helper::get_value()` passing attacker-controlled values from a base64-decoded JSON blob directly to `call_user_func()` without any allowlist validation. This is exploitable by unauthenticated attackers through the `fusion_get_widget_markup` AJAX endpoint, which is registered for non-privileged (unauthenticated) users via `wp_ajax_nopriv_fusion_get_widget_markup`. The endpoint is protected only by a nonce (`fusion_load_nonce`), but this nonce is generated for user ID 0 and is deterministically exposed in the JavaScript output of any public-facing page containing a Post Cards (`[fusion_post_cards]`) or Table of Contents (`[fusion_table_of_contents]`) element. This makes it possible for unauthenticated attackers to execute arbitrar

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-62826

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVSS3: 4.6
0%
Низкий
28 дней назад
nvd логотип
CVE-2026-62825

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
1%
Низкий
21 день назад
nvd логотип
CVE-2026-62824

Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
1%
Низкий
2 дня назад
nvd логотип
CVE-2026-62823

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.

CVSS3: 8.8
1%
Низкий
2 дня назад
nvd логотип
CVE-2026-62822

Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
1%
Низкий
2 дня назад
nvd логотип
CVE-2026-62820

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.

CVSS3: 8.1
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-6281

A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device.

CVSS3: 8.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-62819

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

CVSS3: 8.1
1%
Низкий
2 дня назад
nvd логотип
CVE-2026-62818

Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.

CVSS3: 8.8
1%
Низкий
2 дня назад
nvd логотип
CVE-2026-62817

Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.

CVSS3: 8.8
1%
Низкий
2 дня назад
nvd логотип
CVE-2026-62816

Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.

CVSS3: 8.8
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-62815

Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
1%
Низкий
2 дня назад
nvd логотип
CVE-2026-62814

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

CVSS3: 6.5
1%
Низкий
2 дня назад
nvd логотип
CVE-2026-62812

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-62811

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-6280

Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Nomysem: through 08072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-62807

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-62803

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-62800

Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.

CVSS3: 8.8
1%
Низкий
2 дня назад
nvd логотип
CVE-2026-6279

The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2. This is due to the `wp_conditional_tags` case in `Fusion_Builder_Conditional_Render_Helper::get_value()` passing attacker-controlled values from a base64-decoded JSON blob directly to `call_user_func()` without any allowlist validation. This is exploitable by unauthenticated attackers through the `fusion_get_widget_markup` AJAX endpoint, which is registered for non-privileged (unauthenticated) users via `wp_ajax_nopriv_fusion_get_widget_markup`. The endpoint is protected only by a nonce (`fusion_load_nonce`), but this nonce is generated for user ID 0 and is deterministically exposed in the JavaScript output of any public-facing page containing a Post Cards (`[fusion_post_cards]`) or Table of Contents (`[fusion_table_of_contents]`) element. This makes it possible for unauthenticated attackers to execute arbitrar

CVSS3: 9.8
2%
Низкий
3 месяца назад

Уязвимостей на страницу