Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25 045

Количество 25 045

msrc логотип

CVE-2026-6094

около 1 месяца назад

Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedData

EPSS: Низкий
msrc логотип

CVE-2026-6092

около 1 месяца назад

Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configured

EPSS: Низкий
msrc логотип

CVE-2026-6091

около 1 месяца назад

Partial-chain verification accepts untrusted intermediate as trust anchor

EPSS: Низкий
msrc логотип

CVE-2026-6019

3 месяца назад

BaseCookie.js_output() does not neutralize embedded characters

EPSS: Низкий
msrc логотип

CVE-2026-60147

8 дней назад

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web

EPSS: Низкий
msrc логотип

CVE-2026-60082

12 дней назад

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row

CVSS3: 9.1
EPSS: Низкий
msrc логотип

CVE-2026-60081

16 дней назад

DBI::ProfileData versions before 1.651 for Perl do not limit the path index

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-60005

14 дней назад

NGINX ngx_http_slice_module vulnerability

EPSS: Низкий
msrc логотип

CVE-2026-60002

24 дня назад

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

CVSS3: 7.7
EPSS: Низкий
msrc логотип

CVE-2026-60001

24 дня назад

sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2026-60000

24 дня назад

sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.

CVSS3: 3.7
EPSS: Низкий
msrc логотип

CVE-2026-59999

24 дня назад

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2026-59998

22 дня назад

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.

EPSS: Низкий
msrc логотип

CVE-2026-59997

24 дня назад

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.

CVSS3: 4.2
EPSS: Низкий
msrc логотип

CVE-2026-59996

20 дней назад

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.

CVSS3: 4.2
EPSS: Низкий
msrc логотип

CVE-2026-59995

24 дня назад

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

CVSS3: 4.2
EPSS: Низкий
msrc логотип

CVE-2026-59930

22 дня назад

Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content

EPSS: Низкий
msrc логотип

CVE-2026-59928

22 дня назад

Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions

EPSS: Низкий
msrc логотип

CVE-2026-59926

22 дня назад

Mistune: XSS via unescaped class option in Admonition directive

EPSS: Низкий
msrc логотип

CVE-2026-59925

22 дня назад

inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2026-6094

Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedData

0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2026-6092

Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configured

0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2026-6091

Partial-chain verification accepts untrusted intermediate as trust anchor

0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2026-6019

BaseCookie.js_output() does not neutralize embedded characters

0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-60147

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web

0%
Низкий
8 дней назад
msrc логотип
CVE-2026-60082

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row

CVSS3: 9.1
0%
Низкий
12 дней назад
msrc логотип
CVE-2026-60081

DBI::ProfileData versions before 1.651 for Perl do not limit the path index

CVSS3: 7.5
0%
Низкий
16 дней назад
msrc логотип
CVE-2026-60005

NGINX ngx_http_slice_module vulnerability

1%
Низкий
14 дней назад
msrc логотип
CVE-2026-60002

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

CVSS3: 7.7
0%
Низкий
24 дня назад
msrc логотип
CVE-2026-60001

sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.

CVSS3: 6.5
0%
Низкий
24 дня назад
msrc логотип
CVE-2026-60000

sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.

CVSS3: 3.7
0%
Низкий
24 дня назад
msrc логотип
CVE-2026-59999

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.

CVSS3: 5.9
0%
Низкий
24 дня назад
msrc логотип
CVE-2026-59998

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.

0%
Низкий
22 дня назад
msrc логотип
CVE-2026-59997

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.

CVSS3: 4.2
0%
Низкий
24 дня назад
msrc логотип
CVE-2026-59996

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.

CVSS3: 4.2
0%
Низкий
20 дней назад
msrc логотип
CVE-2026-59995

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

CVSS3: 4.2
0%
Низкий
24 дня назад
msrc логотип
CVE-2026-59930

Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content

0%
Низкий
22 дня назад
msrc логотип
CVE-2026-59928

Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions

0%
Низкий
22 дня назад
msrc логотип
CVE-2026-59926

Mistune: XSS via unescaped class option in Admonition directive

0%
Низкий
22 дня назад
msrc логотип
CVE-2026-59925

inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs

0%
Низкий
22 дня назад

Уязвимостей на страницу