Количество 25 045
Количество 25 045
CVE-2026-6094
Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedData
CVE-2026-6092
Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configured
CVE-2026-6091
Partial-chain verification accepts untrusted intermediate as trust anchor
CVE-2026-6019
BaseCookie.js_output() does not neutralize embedded characters
CVE-2026-60147
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web
CVE-2026-60082
DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row
CVE-2026-60081
DBI::ProfileData versions before 1.651 for Perl do not limit the path index
CVE-2026-60005
NGINX ngx_http_slice_module vulnerability
CVE-2026-60002
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
CVE-2026-60001
sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
CVE-2026-60000
sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.
CVE-2026-59999
In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
CVE-2026-59998
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
CVE-2026-59997
internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.
CVE-2026-59996
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
CVE-2026-59995
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
CVE-2026-59930
Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content
CVE-2026-59928
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
CVE-2026-59926
Mistune: XSS via unescaped class option in Admonition directive
CVE-2026-59925
inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-6094 Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedData | 0% Низкий | около 1 месяца назад | ||
CVE-2026-6092 Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configured | 0% Низкий | около 1 месяца назад | ||
CVE-2026-6091 Partial-chain verification accepts untrusted intermediate as trust anchor | 0% Низкий | около 1 месяца назад | ||
CVE-2026-6019 BaseCookie.js_output() does not neutralize embedded characters | 0% Низкий | 3 месяца назад | ||
CVE-2026-60147 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web | 0% Низкий | 8 дней назад | ||
CVE-2026-60082 DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row | CVSS3: 9.1 | 0% Низкий | 12 дней назад | |
CVE-2026-60081 DBI::ProfileData versions before 1.651 for Perl do not limit the path index | CVSS3: 7.5 | 0% Низкий | 16 дней назад | |
CVE-2026-60005 NGINX ngx_http_slice_module vulnerability | 1% Низкий | 14 дней назад | ||
CVE-2026-60002 ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.) | CVSS3: 7.7 | 0% Низкий | 24 дня назад | |
CVE-2026-60001 sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. | CVSS3: 6.5 | 0% Низкий | 24 дня назад | |
CVE-2026-60000 sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication. | CVSS3: 3.7 | 0% Низкий | 24 дня назад | |
CVE-2026-59999 In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not. | CVSS3: 5.9 | 0% Низкий | 24 дня назад | |
CVE-2026-59998 sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory. | 0% Низкий | 22 дня назад | ||
CVE-2026-59997 internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection. | CVSS3: 4.2 | 0% Низкий | 24 дня назад | |
CVE-2026-59996 scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations. | CVSS3: 4.2 | 0% Низкий | 20 дней назад | |
CVE-2026-59995 sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server. | CVSS3: 4.2 | 0% Низкий | 24 дня назад | |
CVE-2026-59930 Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content | 0% Низкий | 22 дня назад | ||
CVE-2026-59928 Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions | 0% Низкий | 22 дня назад | ||
CVE-2026-59926 Mistune: XSS via unescaped class option in Admonition directive | 0% Низкий | 22 дня назад | ||
CVE-2026-59925 inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs | 0% Низкий | 22 дня назад |
Уязвимостей на страницу