Количество 376 173
Количество 376 173
CVE-2026-62733
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-62732
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62730
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
CVE-2026-6272
A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v2 OpenProviderStream API by sending ProvideSignalRequest. 1. Obtain any valid token with only read scope. 2. Connect to the normal production gRPC API (kuksa.val.v2). 3. Open OpenProviderStream. 4. Send ProvideSignalRequest for a target signal ID. 5. Wait for the broker to forward GetProviderValueRequest. 6. Reply with attacker-controlled GetProviderValueResponse. 7. Other clients performing GetValue / GetValues for that signal receive forged data.
CVE-2026-62729
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62728
Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-62726
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62725
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62724
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62723
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62722
Heap-based buffer overflow in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-62721
Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.
CVE-2026-62720
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-6271
The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler. This is due to missing file type validation. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.
CVE-2026-62719
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
CVE-2026-62718
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-62717
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
CVE-2026-62716
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-62715
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-62714
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-62733 Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62732 Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62730 Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 3 дня назад | |
CVE-2026-6272 A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v2 OpenProviderStream API by sending ProvideSignalRequest. 1. Obtain any valid token with only read scope. 2. Connect to the normal production gRPC API (kuksa.val.v2). 3. Open OpenProviderStream. 4. Send ProvideSignalRequest for a target signal ID. 5. Wait for the broker to forward GetProviderValueRequest. 6. Reply with attacker-controlled GetProviderValueResponse. 7. Other clients performing GetValue / GetValues for that signal receive forged data. | 0% Низкий | 4 месяца назад | ||
CVE-2026-62729 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 3 дня назад | |
CVE-2026-62728 Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 3 дня назад | |
CVE-2026-62726 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 3 дня назад | |
CVE-2026-62725 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 3 дня назад | |
CVE-2026-62724 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 3 дня назад | |
CVE-2026-62723 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 3 дня назад | |
CVE-2026-62722 Heap-based buffer overflow in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62721 Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62720 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | CVSS3: 6.5 | 0% Низкий | 3 дня назад | |
CVE-2026-6271 The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler. This is due to missing file type validation. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. | CVSS3: 9.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-62719 Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62718 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | CVSS3: 6.5 | 0% Низкий | 3 дня назад | |
CVE-2026-62717 Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62716 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | CVSS3: 6.5 | 0% Низкий | 3 дня назад | |
CVE-2026-62715 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | CVSS3: 6.5 | 0% Низкий | 3 дня назад | |
CVE-2026-62714 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | CVSS3: 6.5 | 0% Низкий | 3 дня назад |
Уязвимостей на страницу