Количество 376 565
Количество 376 565
CVE-2026-62889
Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
CVE-2026-62888
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-62887
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
CVE-2026-62886
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2026-62885
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-62883
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-62882
Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-62881
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-62880
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-6287
The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blockUniqId' block attribute in multiple Product Gride blocks in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-62878
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
CVE-2026-62877
Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-62876
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-62873
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62872
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
CVE-2026-62871
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-62870
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
CVE-2026-62869
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.
CVE-2026-62857
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1, 2.2, and 2.3 maintenance lines, getNodeInfo() follows an attacker-controlled links[].href value from /.well-known/nodeinfo without scheme, redirect, or private-address validation, allowing requests to loopback, link-local, cloud metadata, and private-network services and returning their response bodies. This issue is fixed in versions 1.9.13, 1.10.12, 2.0.22, 2.1.18, 2.2.7, and 2.3.2.
CVE-2026-6284
An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no password input limiters makes brute force password enumeration possible.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-62889 Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. | CVSS3: 8.1 | 1% Низкий | 3 дня назад | |
CVE-2026-62888 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 2% Низкий | 3 дня назад | |
CVE-2026-62887 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 3 дня назад | |
CVE-2026-62886 Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62885 Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62883 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | CVSS3: 6.7 | 0% Низкий | 3 дня назад | |
CVE-2026-62882 Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | CVSS3: 4.3 | 1% Низкий | 3 дня назад | |
CVE-2026-62881 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | CVSS3: 6.7 | 0% Низкий | 3 дня назад | |
CVE-2026-62880 Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-6287 The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blockUniqId' block attribute in multiple Product Gride blocks in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-62878 Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. | CVSS3: 9.8 | 1% Низкий | 3 дня назад | |
CVE-2026-62877 Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62876 Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62873 Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. | CVSS3: 9.8 | 0% Низкий | 7 дней назад | |
CVE-2026-62872 Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. | CVSS3: 8.8 | 1% Низкий | 3 дня назад | |
CVE-2026-62871 Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62870 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. | CVSS3: 8.8 | 1% Низкий | 10 дней назад | |
CVE-2026-62869 Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network. | CVSS3: 8.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62857 Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1, 2.2, and 2.3 maintenance lines, getNodeInfo() follows an attacker-controlled links[].href value from /.well-known/nodeinfo without scheme, redirect, or private-address validation, allowing requests to loopback, link-local, cloud metadata, and private-network services and returning their response bodies. This issue is fixed in versions 1.9.13, 1.10.12, 2.0.22, 2.1.18, 2.2.7, and 2.3.2. | 0% Низкий | 7 дней назад | ||
CVE-2026-6284 An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no password input limiters makes brute force password enumeration possible. | CVSS3: 9.1 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу