Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 173

Количество 376 173

nvd логотип

CVE-2026-62778

2 дня назад

Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-62777

2 дня назад

Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62776

2 дня назад

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62775

2 дня назад

Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-62774

2 дня назад

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-62773

2 дня назад

Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-62772

2 дня назад

Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62771

2 дня назад

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62770

2 дня назад

Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-6276

3 месяца назад

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-62769

2 дня назад

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2026-62768

2 дня назад

Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62766

2 дня назад

Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-62764

28 дней назад

Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user without system permissions may issue a remote command to gracefully shutdown system components (compaction-coordinator, compactor, gc, manager, monitor, tserver, or sserver), leading to a denial of service. This issue affects Apache Accumulo 2.1.4 and 2.1.5. Users are recommended to upgrade to version 2.1.6, which fixes the issue.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-62761

2 дня назад

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-6275

3 месяца назад

The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 This is due to insufficient output escaping on the post author's nickname in the statcounter_addToTags() function. The function is hooked to wp_head and fires on every single post page. It retrieves the post author's nickname via the_author_meta() and echoes it directly into a JavaScript double-quoted string context inside a <script> block without applying esc_js() or any equivalent JavaScript-context escaping. This makes it possible for authenticated attackers with Author-level access and above to inject arbitrary web scripts into pages that will execute whenever any user (including unauthenticated visitors) accesses a post authored by the attacker.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2026-62758

2 дня назад

Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62757

2 дня назад

Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-62755

2 дня назад

Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62754

2 дня назад

Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-62778

Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 8.1
1%
Низкий
2 дня назад
nvd логотип
CVE-2026-62777

Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-62776

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-62775

Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-62774

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-62773

Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-62772

Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-62771

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-62770

Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-6276

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.

CVSS3: 7.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-62769

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

CVSS3: 6.7
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-62768

Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-62766

Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.

CVSS3: 7
1%
Низкий
2 дня назад
nvd логотип
CVE-2026-62764

Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user without system permissions may issue a remote command to gracefully shutdown system components (compaction-coordinator, compactor, gc, manager, monitor, tserver, or sserver), leading to a denial of service. This issue affects Apache Accumulo 2.1.4 and 2.1.5. Users are recommended to upgrade to version 2.1.6, which fixes the issue.

CVSS3: 6.5
0%
Низкий
28 дней назад
nvd логотип
CVE-2026-62761

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-6275

The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 This is due to insufficient output escaping on the post author's nickname in the statcounter_addToTags() function. The function is hooked to wp_head and fires on every single post page. It retrieves the post author's nickname via the_author_meta() and echoes it directly into a JavaScript double-quoted string context inside a <script> block without applying esc_js() or any equivalent JavaScript-context escaping. This makes it possible for authenticated attackers with Author-level access and above to inject arbitrary web scripts into pages that will execute whenever any user (including unauthenticated visitors) accesses a post authored by the attacker.

CVSS3: 6.4
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-62758

Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-62757

Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.

CVSS3: 5.3
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-62755

Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-62754

Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
2 дня назад

Уязвимостей на страницу