Количество 378 322
Количество 378 322
CVE-2026-61950
Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
CVE-2026-6194
A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_410188 of the file /boafrm/formWlanSetup of the component HTTP Request Handler. This manipulation of the argument wan-url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
CVE-2026-61949
Unauthenticated SQL Injection in Bookly <= 27.7 versions.
CVE-2026-61948
Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.
CVE-2026-61947
Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.
CVE-2026-61946
Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
CVE-2026-61945
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.
CVE-2026-61944
Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.
CVE-2026-61943
Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
CVE-2026-6193
A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1.1. Affected is an unknown function of the file /register.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
CVE-2026-61939
Use after free in Winlogon allows an authorized attacker to elevate privileges locally.
CVE-2026-61938
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-61937
Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
CVE-2026-61936
Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.
CVE-2026-61934
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-61933
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2026-61932
Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-61930
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-6192
A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is 839936aa33eb8899bbbd80fda02796bb65068951. It is suggested to install a patch to address this issue.
CVE-2026-61929
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-61950 Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. | CVSS3: 9.3 | 0% Низкий | 25 дней назад | |
CVE-2026-6194 A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_410188 of the file /boafrm/formWlanSetup of the component HTTP Request Handler. This manipulation of the argument wan-url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
CVE-2026-61949 Unauthenticated SQL Injection in Bookly <= 27.7 versions. | CVSS3: 9.3 | 0% Низкий | 25 дней назад | |
CVE-2026-61948 Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions. | CVSS3: 9.3 | 0% Низкий | 25 дней назад | |
CVE-2026-61947 Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions. | CVSS3: 7.1 | 0% Низкий | 25 дней назад | |
CVE-2026-61946 Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions. | CVSS3: 6.5 | 0% Низкий | 25 дней назад | |
CVE-2026-61945 Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6. | CVSS3: 6.5 | 0% Низкий | 25 дней назад | |
CVE-2026-61944 Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions. | CVSS3: 7.1 | 0% Низкий | 25 дней назад | |
CVE-2026-61943 Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions. | CVSS3: 7.5 | 0% Низкий | 25 дней назад | |
CVE-2026-6193 A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1.1. Affected is an unknown function of the file /register.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. | CVSS3: 7.3 | 0% Низкий | 4 месяца назад | |
CVE-2026-61939 Use after free in Winlogon allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 6 дней назад | |
CVE-2026-61938 Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 6 дней назад | |
CVE-2026-61937 Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 6 дней назад | |
CVE-2026-61936 Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally. | CVSS3: 5.5 | 0% Низкий | 6 дней назад | |
CVE-2026-61934 Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 6 дней назад | |
CVE-2026-61933 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 6 дней назад | |
CVE-2026-61932 Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 6 дней назад | |
CVE-2026-61930 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 2% Низкий | 6 дней назад | |
CVE-2026-6192 A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is 839936aa33eb8899bbbd80fda02796bb65068951. It is suggested to install a patch to address this issue. | CVSS3: 3.3 | 0% Низкий | 4 месяца назад | |
CVE-2026-61929 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 2% Низкий | 6 дней назад |
Уязвимостей на страницу