Количество 377 179
Количество 377 179
CVE-2026-61367
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
CVE-2026-61366
Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.
CVE-2026-61365
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
CVE-2026-61364
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
CVE-2026-61363
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-61361
Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.
CVE-2026-61360
Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
CVE-2026-6135
A weakness has been identified in Tenda F451 1.0.0.7_cn_svn7958. This issue affects the function fromSetIpBind of the file /goform/SetIpBind. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
CVE-2026-61359
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
CVE-2026-61358
Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
CVE-2026-61357
Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.
CVE-2026-61356
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
CVE-2026-61355
Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
CVE-2026-61353
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-61352
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-61350
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-6134
A security flaw has been discovered in Tenda F451 1.0.0.7_cn_svn7958. This vulnerability affects the function fromqossetting of the file /goform/qossetting. Performing a manipulation of the argument qos results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
CVE-2026-61349
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
CVE-2026-61348
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-61347
Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-61367 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 4 дня назад | |
CVE-2026-61366 Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 4 дня назад | |
CVE-2026-61365 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 4 дня назад | |
CVE-2026-61364 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 4 дня назад | |
CVE-2026-61363 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | CVSS3: 7.5 | 1% Низкий | 4 дня назад | |
CVE-2026-61361 Use after free in Windows DHCP Client allows an authorized attacker to execute code locally. | CVSS3: 7 | 0% Низкий | 4 дня назад | |
CVE-2026-61360 Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 4 дня назад | |
CVE-2026-6135 A weakness has been identified in Tenda F451 1.0.0.7_cn_svn7958. This issue affects the function fromSetIpBind of the file /goform/SetIpBind. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. | CVSS3: 8.8 | 1% Низкий | 4 месяца назад | |
CVE-2026-61359 Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 4 дня назад | |
CVE-2026-61358 Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 4% Низкий | 4 дня назад | |
CVE-2026-61357 Use after free in Application Information Services allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 4 дня назад | |
CVE-2026-61356 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 4 дня назад | |
CVE-2026-61355 Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 4 дня назад | |
CVE-2026-61353 Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 4 дня назад | |
CVE-2026-61352 Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | CVSS3: 7.5 | 0% Низкий | 4 дня назад | |
CVE-2026-61350 Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. | CVSS3: 4.6 | 0% Низкий | 4 дня назад | |
CVE-2026-6134 A security flaw has been discovered in Tenda F451 1.0.0.7_cn_svn7958. This vulnerability affects the function fromqossetting of the file /goform/qossetting. Performing a manipulation of the argument qos results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. | CVSS3: 8.8 | 1% Низкий | 4 месяца назад | |
CVE-2026-61349 Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 4 дня назад | |
CVE-2026-61348 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 2% Низкий | 4 дня назад | |
CVE-2026-61347 Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 4 дня назад |
Уязвимостей на страницу