Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 173

Количество 376 173

nvd логотип

CVE-2026-62713

3 дня назад

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62712

3 дня назад

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62711

3 дня назад

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62710

3 дня назад

Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-6270

4 месяца назад

@fastify/middie versions 9.3.1 and earlier do not register inherited middleware directly on child plugin engine instances. When a Fastify application registers authentication middleware in a parent scope and then registers child plugins with @fastify/middie, the child scope does not inherit the parent middleware. This allows unauthenticated requests to reach routes defined in child plugin scopes, bypassing authentication and authorization checks. Upgrade to @fastify/middie 9.3.2 to fix this issue. There are no workarounds.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-62709

3 дня назад

Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-62708

3 дня назад

Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2026-62707

3 дня назад

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62705

3 дня назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-62703

3 дня назад

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-62702

3 дня назад

Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2026-62701

3 дня назад

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62700

3 дня назад

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-6269

2 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to modify hidden merge requests due to incorrect authorization enforcements.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-62699

3 дня назад

Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2026-62698

3 дня назад

Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62696

3 дня назад

Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62695

3 дня назад

Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62693

3 дня назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-62692

3 дня назад

Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-62713

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
2%
Низкий
3 дня назад
nvd логотип
CVE-2026-62712

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62711

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62710

Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-6270

@fastify/middie versions 9.3.1 and earlier do not register inherited middleware directly on child plugin engine instances. When a Fastify application registers authentication middleware in a parent scope and then registers child plugins with @fastify/middie, the child scope does not inherit the parent middleware. This allows unauthenticated requests to reach routes defined in child plugin scopes, bypassing authentication and authorization checks. Upgrade to @fastify/middie 9.3.2 to fix this issue. There are no workarounds.

CVSS3: 9.1
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-62709

Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62708

Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.

CVSS3: 6.4
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62707

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62705

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62703

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62702

Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.

CVSS3: 6.8
1%
Низкий
3 дня назад
nvd логотип
CVE-2026-62701

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62700

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-6269

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to modify hidden merge requests due to incorrect authorization enforcements.

CVSS3: 5.4
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-62699

Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.

CVSS3: 6.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62698

Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62696

Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
3%
Низкий
3 дня назад
nvd логотип
CVE-2026-62695

Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62693

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62692

Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад

Уязвимостей на страницу