Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 565

Количество 376 565

nvd логотип

CVE-2026-6193

4 месяца назад

A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1.1. Affected is an unknown function of the file /register.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2026-61939

3 дня назад

Use after free in Winlogon allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-61938

3 дня назад

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-61937

3 дня назад

Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-61936

3 дня назад

Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-61934

3 дня назад

Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-61933

3 дня назад

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-61932

3 дня назад

Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-61930

3 дня назад

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-6192

4 месяца назад

A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is 839936aa33eb8899bbbd80fda02796bb65068951. It is suggested to install a patch to address this issue.

CVSS3: 3.3
EPSS: Низкий
nvd логотип

CVE-2026-61929

3 дня назад

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-61928

3 дня назад

Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-61927

3 дня назад

Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-61926

3 дня назад

Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-61925

3 дня назад

Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-61924

3 дня назад

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-61923

3 дня назад

Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-61921

3 дня назад

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-61920

3 дня назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.

CVSS3: 6.6
EPSS: Низкий
nvd логотип

CVE-2026-6191

4 месяца назад

A vulnerability was determined in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /equipments.php. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-6193

A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1.1. Affected is an unknown function of the file /register.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

CVSS3: 7.3
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-61939

Use after free in Winlogon allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-61938

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-61937

Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-61936

Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.

CVSS3: 5.5
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-61934

Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-61933

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-61932

Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-61930

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
2%
Низкий
3 дня назад
nvd логотип
CVE-2026-6192

A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is 839936aa33eb8899bbbd80fda02796bb65068951. It is suggested to install a patch to address this issue.

CVSS3: 3.3
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-61929

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVSS3: 7
1%
Низкий
3 дня назад
nvd логотип
CVE-2026-61928

Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.

CVSS3: 5.5
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-61927

Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-61926

Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-61925

Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-61924

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
1%
Низкий
3 дня назад
nvd логотип
CVE-2026-61923

Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-61921

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
1%
Низкий
3 дня назад
nvd логотип
CVE-2026-61920

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.

CVSS3: 6.6
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-6191

A vulnerability was determined in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /equipments.php. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

CVSS3: 6.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу