Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 565

Количество 376 565

nvd логотип

CVE-2026-62889

3 дня назад

Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-62888

3 дня назад

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62887

3 дня назад

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-62886

3 дня назад

Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62885

3 дня назад

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62883

3 дня назад

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2026-62882

3 дня назад

Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-62881

3 дня назад

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2026-62880

3 дня назад

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-6287

3 месяца назад

The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blockUniqId' block attribute in multiple Product Gride blocks in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-62878

3 дня назад

Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-62877

3 дня назад

Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62876

3 дня назад

Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62873

7 дней назад

Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-62872

3 дня назад

Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-62871

3 дня назад

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62870

10 дней назад

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-62869

3 дня назад

Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-62857

7 дней назад

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1, 2.2, and 2.3 maintenance lines, getNodeInfo() follows an attacker-controlled links[].href value from /.well-known/nodeinfo without scheme, redirect, or private-address validation, allowing requests to loopback, link-local, cloud metadata, and private-network services and returning their response bodies. This issue is fixed in versions 1.9.13, 1.10.12, 2.0.22, 2.1.18, 2.2.7, and 2.3.2.

EPSS: Низкий
nvd логотип

CVE-2026-6284

4 месяца назад

An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no password input limiters makes brute force password enumeration possible.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-62889

Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.1
1%
Низкий
3 дня назад
nvd логотип
CVE-2026-62888

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
2%
Низкий
3 дня назад
nvd логотип
CVE-2026-62887

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62886

Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62885

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62883

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

CVSS3: 6.7
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62882

Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 4.3
1%
Низкий
3 дня назад
nvd логотип
CVE-2026-62881

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

CVSS3: 6.7
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62880

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-6287

The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blockUniqId' block attribute in multiple Product Gride blocks in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 5.4
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-62878

Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
1%
Низкий
3 дня назад
nvd логотип
CVE-2026-62877

Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62876

Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62873

Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 9.8
0%
Низкий
7 дней назад
nvd логотип
CVE-2026-62872

Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.8
1%
Низкий
3 дня назад
nvd логотип
CVE-2026-62871

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62870

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
1%
Низкий
10 дней назад
nvd логотип
CVE-2026-62869

Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.

CVSS3: 8.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62857

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1, 2.2, and 2.3 maintenance lines, getNodeInfo() follows an attacker-controlled links[].href value from /.well-known/nodeinfo without scheme, redirect, or private-address validation, allowing requests to loopback, link-local, cloud metadata, and private-network services and returning their response bodies. This issue is fixed in versions 1.9.13, 1.10.12, 2.0.22, 2.1.18, 2.2.7, and 2.3.2.

0%
Низкий
7 дней назад
nvd логотип
CVE-2026-6284

An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no password input limiters makes brute force password enumeration possible.

CVSS3: 9.1
0%
Низкий
4 месяца назад

Уязвимостей на страницу