Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 565

Количество 376 565

nvd логотип

CVE-2026-62845

14 дней назад

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivers build DDL statements by interpolating the user-supplied DataStoreUsername/DataStoreSchema directly into SQL via fmt.Sprintf, without escaping identifiers. These fields have no format validation, so a value containing a quote character breaks out of the quoted identifier — SQL injection executed over Kamaji's root connection to the shared datastore. etcd driver is not affected.This issue is fixed in version 26.7.4-edge.

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2026-62843

30 дней назад

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses strings.ReplaceAll(nameInArchive, "\", "/"), which turns a POSIX filename such as ..\..\evil.sh into the archive entry ../../evil.sh, allowing a user with upload permission to plant a backslash-named file that escapes the extraction directory when another user downloads and extracts the generated zip or tar archive. This issue is fixed in version 2.63.17.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2026-62842

3 дня назад

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-6283

около 1 месяца назад

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from v.4.8.2.23 before v.4.8.3.1.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-62839

3 дня назад

Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-62837

3 дня назад

Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-62836

7 дней назад

Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2026-62835

21 день назад

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-62832

3 дня назад

Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-62830

7 дней назад

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

CVSS3: 9.9
EPSS: Низкий
nvd логотип

CVE-2026-6282

3 месяца назад

A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access files belonging to other users on the same device.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-62829

3 дня назад

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVSS3: 4.6
EPSS: Низкий
nvd логотип

CVE-2026-62828

17 дней назад

Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-62827

3 дня назад

Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-62826

28 дней назад

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVSS3: 4.6
EPSS: Низкий
nvd логотип

CVE-2026-62825

21 день назад

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
EPSS: Низкий
nvd логотип

CVE-2026-62824

3 дня назад

Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-62823

3 дня назад

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-62822

3 дня назад

Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-62820

3 дня назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-62845

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivers build DDL statements by interpolating the user-supplied DataStoreUsername/DataStoreSchema directly into SQL via fmt.Sprintf, without escaping identifiers. These fields have no format validation, so a value containing a quote character breaks out of the quoted identifier — SQL injection executed over Kamaji's root connection to the shared datastore. etcd driver is not affected.This issue is fixed in version 26.7.4-edge.

CVSS3: 4.7
0%
Низкий
14 дней назад
nvd логотип
CVE-2026-62843

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses strings.ReplaceAll(nameInArchive, "\", "/"), which turns a POSIX filename such as ..\..\evil.sh into the archive entry ../../evil.sh, allowing a user with upload permission to plant a backslash-named file that escapes the extraction directory when another user downloads and extracts the generated zip or tar archive. This issue is fixed in version 2.63.17.

CVSS3: 6.8
0%
Низкий
30 дней назад
nvd логотип
CVE-2026-62842

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-6283

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from v.4.8.2.23 before v.4.8.3.1.

CVSS3: 5.4
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-62839

Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVSS3: 6.5
1%
Низкий
3 дня назад
nvd логотип
CVE-2026-62837

Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

CVSS3: 6.5
1%
Низкий
3 дня назад
nvd логотип
CVE-2026-62836

Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 8.7
0%
Низкий
7 дней назад
nvd логотип
CVE-2026-62835

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

CVSS3: 9.3
1%
Низкий
21 день назад
nvd логотип
CVE-2026-62832

Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
2%
Низкий
3 дня назад
nvd логотип
CVE-2026-62830

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

CVSS3: 9.9
0%
Низкий
7 дней назад
nvd логотип
CVE-2026-6282

A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access files belonging to other users on the same device.

CVSS3: 8.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-62829

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVSS3: 4.6
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-62828

Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network.

CVSS3: 5.4
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-62827

Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.8
1%
Низкий
3 дня назад
nvd логотип
CVE-2026-62826

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVSS3: 4.6
0%
Низкий
28 дней назад
nvd логотип
CVE-2026-62825

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
1%
Низкий
21 день назад
nvd логотип
CVE-2026-62824

Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
1%
Низкий
3 дня назад
nvd логотип
CVE-2026-62823

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.

CVSS3: 8.8
1%
Низкий
3 дня назад
nvd логотип
CVE-2026-62822

Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
1%
Низкий
3 дня назад
nvd логотип
CVE-2026-62820

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.

CVSS3: 8.1
0%
Низкий
3 дня назад

Уязвимостей на страницу