Количество 376 565
Количество 376 565
CVE-2026-6281
A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device.
CVE-2026-62819
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
CVE-2026-62818
Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.
CVE-2026-62817
Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.
CVE-2026-62816
Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.
CVE-2026-62815
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
CVE-2026-62814
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-62812
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
CVE-2026-62811
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
CVE-2026-6280
Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Nomysem: through 08072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-62807
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
CVE-2026-62803
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
CVE-2026-62800
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
CVE-2026-6279
The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2. This is due to the `wp_conditional_tags` case in `Fusion_Builder_Conditional_Render_Helper::get_value()` passing attacker-controlled values from a base64-decoded JSON blob directly to `call_user_func()` without any allowlist validation. This is exploitable by unauthenticated attackers through the `fusion_get_widget_markup` AJAX endpoint, which is registered for non-privileged (unauthenticated) users via `wp_ajax_nopriv_fusion_get_widget_markup`. The endpoint is protected only by a nonce (`fusion_load_nonce`), but this nonce is generated for user ID 0 and is deterministically exposed in the JavaScript output of any public-facing page containing a Post Cards (`[fusion_post_cards]`) or Table of Contents (`[fusion_table_of_contents]`) element. This makes it possible for unauthenticated attackers to execute arbitrar
CVE-2026-62799
Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.
CVE-2026-62798
Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-62797
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-62796
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
CVE-2026-62795
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
CVE-2026-62793
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-6281 A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device. | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-62819 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine | CVSS3: 8.1 | 1% Низкий | 3 дня назад | |
CVE-2026-62818 Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network. | CVSS3: 8.8 | 1% Низкий | 3 дня назад | |
CVE-2026-62817 Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network. | CVSS3: 8.8 | 1% Низкий | 3 дня назад | |
CVE-2026-62816 Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. | CVSS3: 8.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62815 Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. | CVSS3: 9.8 | 1% Низкий | 3 дня назад | |
CVE-2026-62814 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | CVSS3: 6.5 | 1% Низкий | 3 дня назад | |
CVE-2026-62812 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62811 Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-6280 Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Nomysem: through 08072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-62807 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62803 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62800 Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. | CVSS3: 8.8 | 1% Низкий | 3 дня назад | |
CVE-2026-6279 The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2. This is due to the `wp_conditional_tags` case in `Fusion_Builder_Conditional_Render_Helper::get_value()` passing attacker-controlled values from a base64-decoded JSON blob directly to `call_user_func()` without any allowlist validation. This is exploitable by unauthenticated attackers through the `fusion_get_widget_markup` AJAX endpoint, which is registered for non-privileged (unauthenticated) users via `wp_ajax_nopriv_fusion_get_widget_markup`. The endpoint is protected only by a nonce (`fusion_load_nonce`), but this nonce is generated for user ID 0 and is deterministically exposed in the JavaScript output of any public-facing page containing a Post Cards (`[fusion_post_cards]`) or Table of Contents (`[fusion_table_of_contents]`) element. This makes it possible for unauthenticated attackers to execute arbitrar | CVSS3: 9.8 | 2% Низкий | 3 месяца назад | |
CVE-2026-62799 Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62798 Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 3 дня назад | |
CVE-2026-62797 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62796 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 3 дня назад | |
CVE-2026-62795 Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | CVSS3: 8.8 | 1% Низкий | 3 дня назад | |
CVE-2026-62793 Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 3 дня назад |
Уязвимостей на страницу