Количество 376 565
Количество 376 565
CVE-2026-62915
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
CVE-2026-62914
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
CVE-2026-62913
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-62912
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
CVE-2026-62911
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-62910
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-6290
Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token. This allows an authenticated GUI user with access in one org, to use the query() plugin, in a notebook cell, to run VQL queries on other orgs which they may not have access to. The user's permissions in the other org are the same as the permissions they have in the org containing the notebook.
CVE-2026-62909
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-62908
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
CVE-2026-62902
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-62901
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-62900
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-62899
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-62898
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
CVE-2026-62897
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-62896
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
CVE-2026-62894
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-62893
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
CVE-2026-62892
Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
CVE-2026-62890
Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-62915 Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. | CVSS3: 6.5 | 0% Низкий | 3 дня назад | |
CVE-2026-62914 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | CVSS3: 7.3 | 1% Низкий | 3 дня назад | |
CVE-2026-62913 Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | CVSS3: 8.8 | 1% Низкий | 3 дня назад | |
CVE-2026-62912 Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network. | CVSS3: 6.5 | 1% Низкий | 3 дня назад | |
CVE-2026-62911 Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | CVSS3: 8 | 1% Низкий | 3 дня назад | |
CVE-2026-62910 Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | CVSS3: 7.2 | 1% Низкий | 3 дня назад | |
CVE-2026-6290 Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token. This allows an authenticated GUI user with access in one org, to use the query() plugin, in a notebook cell, to run VQL queries on other orgs which they may not have access to. The user's permissions in the other org are the same as the permissions they have in the org containing the notebook. | CVSS3: 8 | 0% Низкий | 4 месяца назад | |
CVE-2026-62909 Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62908 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 3 дня назад | |
CVE-2026-62902 Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. | CVSS3: 6.5 | 1% Низкий | 3 дня назад | |
CVE-2026-62901 Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. | CVSS3: 7.5 | 1% Низкий | 3 дня назад | |
CVE-2026-62900 Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network. | CVSS3: 5.9 | 1% Низкий | 3 дня назад | |
CVE-2026-62899 Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. | CVSS3: 5.9 | 1% Низкий | 3 дня назад | |
CVE-2026-62898 Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. | CVSS3: 7.5 | 1% Низкий | 3 дня назад | |
CVE-2026-62897 Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. | CVSS3: 7 | 0% Низкий | 3 дня назад | |
CVE-2026-62896 Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. | CVSS3: 9.6 | 0% Низкий | 7 дней назад | |
CVE-2026-62894 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62893 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | CVSS3: 9.8 | 2% Низкий | 3 дня назад | |
CVE-2026-62892 Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 3 дня назад | |
CVE-2026-62890 Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад |
Уязвимостей на страницу