Количество 376 173
Количество 376 173
CVE-2026-62778
Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62777
Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-62776
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
CVE-2026-62775
Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.
CVE-2026-62774
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-62773
Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
CVE-2026-62772
Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally.
CVE-2026-62771
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-62770
Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.
CVE-2026-6276
Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.
CVE-2026-62769
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-62768
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-62766
Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
CVE-2026-62764
Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user without system permissions may issue a remote command to gracefully shutdown system components (compaction-coordinator, compactor, gc, manager, monitor, tserver, or sserver), leading to a denial of service. This issue affects Apache Accumulo 2.1.4 and 2.1.5. Users are recommended to upgrade to version 2.1.6, which fixes the issue.
CVE-2026-62761
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
CVE-2026-6275
The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 This is due to insufficient output escaping on the post author's nickname in the statcounter_addToTags() function. The function is hooked to wp_head and fires on every single post page. It retrieves the post author's nickname via the_author_meta() and echoes it directly into a JavaScript double-quoted string context inside a <script> block without applying esc_js() or any equivalent JavaScript-context escaping. This makes it possible for authenticated attackers with Author-level access and above to inject arbitrary web scripts into pages that will execute whenever any user (including unauthenticated visitors) accesses a post authored by the attacker.
CVE-2026-62758
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-62757
Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-62755
Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.
CVE-2026-62754
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-62778 Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network. | CVSS3: 8.1 | 1% Низкий | 2 дня назад | |
CVE-2026-62777 Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 2 дня назад | |
CVE-2026-62776 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 2 дня назад | |
CVE-2026-62775 Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 2 дня назад | |
CVE-2026-62774 Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 2 дня назад | |
CVE-2026-62773 Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 2 дня назад | |
CVE-2026-62772 Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 2 дня назад | |
CVE-2026-62771 Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 2 дня назад | |
CVE-2026-62770 Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 2 дня назад | |
CVE-2026-6276 Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-62769 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | CVSS3: 6.7 | 0% Низкий | 2 дня назад | |
CVE-2026-62768 Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 2 дня назад | |
CVE-2026-62766 Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 1% Низкий | 2 дня назад | |
CVE-2026-62764 Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user without system permissions may issue a remote command to gracefully shutdown system components (compaction-coordinator, compactor, gc, manager, monitor, tserver, or sserver), leading to a denial of service. This issue affects Apache Accumulo 2.1.4 and 2.1.5. Users are recommended to upgrade to version 2.1.6, which fixes the issue. | CVSS3: 6.5 | 0% Низкий | 28 дней назад | |
CVE-2026-62761 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 2 дня назад | |
CVE-2026-6275 The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 This is due to insufficient output escaping on the post author's nickname in the statcounter_addToTags() function. The function is hooked to wp_head and fires on every single post page. It retrieves the post author's nickname via the_author_meta() and echoes it directly into a JavaScript double-quoted string context inside a <script> block without applying esc_js() or any equivalent JavaScript-context escaping. This makes it possible for authenticated attackers with Author-level access and above to inject arbitrary web scripts into pages that will execute whenever any user (including unauthenticated visitors) accesses a post authored by the attacker. | CVSS3: 6.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-62758 Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 2 дня назад | |
CVE-2026-62757 Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network. | CVSS3: 5.3 | 0% Низкий | 2 дня назад | |
CVE-2026-62755 Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 2 дня назад | |
CVE-2026-62754 Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 2 дня назад |
Уязвимостей на страницу