Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 969

Количество 77 969

ubuntu логотип

CVE-2026-3906

6 месяцев назад

WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collaboration annotations) was introduced in WordPress 6.9 to allow editorial comments directly on posts in the block editor. However, the REST API `create_item_permissions_check()` method in the comments controller did not verify that the authenticated user has `edit_post` permission on the target post when creating a note. This makes it possible for authenticated attackers with Subscriber-level access to create notes on any post, including posts authored by other users, private posts, and posts in any status.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2026-3904

6 месяцев назад

Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library version 2.36 under high load on x86_64 systems, the client may call memcmp on inputs that are concurrently modified by other processes or threads and crash. The nscd client in the GNU C Library uses the memcmp function with inputs that may be concurrently modified by another thread, potentially resulting in spurious cache misses, which in itself is not a security issue.  However in the GNU C Library version 2.36 an optimized implementation of memcmp was introduced for x86_64 which could crash when invoked with such undefined behaviour, turning this into a potential crash of the nscd client and the application that uses it. This implementation was backported to the 2.35 branch, making the nscd client in that branch vulnerable as well.  Subsequently, the fix for this issue was backported to all vulnerable branches in the GNU C Library repository. It is advised that ...

CVSS3: 6.2
EPSS: Низкий
ubuntu логотип

CVE-2026-39044

3 месяца назад

Integer overflow in WAV parser cue handling

EPSS: Низкий
ubuntu логотип

CVE-2026-39043

3 месяца назад

Heap buffer overflow in Matroska demuxer

EPSS: Низкий
ubuntu логотип

CVE-2026-3902

5 месяцев назад

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) to a single version with underscores. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-39020

4 дня назад

(An issue in WIngs3D v.2.4.1 allows a local attacker to cause a denial ...)

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2026-38978

3 месяца назад

transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2026-38974

около 2 месяцев назад

Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2026-38969

2 месяца назад

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

EPSS: Низкий
ubuntu логотип

CVE-2026-38968

2 месяца назад

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2026-3890

5 месяцев назад

[hcd-ohci: infinite loop]

EPSS: Низкий
ubuntu логотип

CVE-2026-3889

6 месяцев назад

Spoofing issue in Thunderbird. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-3888

6 месяцев назад

Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2026-3886

2 месяца назад

[virtio-gpu: fix overflow check when allocating 2d image]

EPSS: Низкий
ubuntu логотип

CVE-2026-3884

6 месяцев назад

Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that allows a creation of more than 1 alert for each 'target' element. An attacker would need to set an arbitrary key-value pair on Object.prototype through a crafted URL achieving a prototype pollution first, before being able to execute arbitrary JavaScript in the context of the user's browser.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2026-38822

17 дней назад

In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.

CVSS3: 7.6
EPSS: Низкий
ubuntu логотип

CVE-2026-38821

17 дней назад

A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2026-38820

17 дней назад

openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.

CVSS3: 8.3
EPSS: Низкий
ubuntu логотип

CVE-2026-38819

17 дней назад

Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2026-38755

около 2 месяцев назад

A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

CVSS3: 2.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-3906

WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collaboration annotations) was introduced in WordPress 6.9 to allow editorial comments directly on posts in the block editor. However, the REST API `create_item_permissions_check()` method in the comments controller did not verify that the authenticated user has `edit_post` permission on the target post when creating a note. This makes it possible for authenticated attackers with Subscriber-level access to create notes on any post, including posts authored by other users, private posts, and posts in any status.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2026-3904

Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library version 2.36 under high load on x86_64 systems, the client may call memcmp on inputs that are concurrently modified by other processes or threads and crash. The nscd client in the GNU C Library uses the memcmp function with inputs that may be concurrently modified by another thread, potentially resulting in spurious cache misses, which in itself is not a security issue.  However in the GNU C Library version 2.36 an optimized implementation of memcmp was introduced for x86_64 which could crash when invoked with such undefined behaviour, turning this into a potential crash of the nscd client and the application that uses it. This implementation was backported to the 2.35 branch, making the nscd client in that branch vulnerable as well.  Subsequently, the fix for this issue was backported to all vulnerable branches in the GNU C Library repository. It is advised that ...

CVSS3: 6.2
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2026-39044

Integer overflow in WAV parser cue handling

3 месяца назад
ubuntu логотип
CVE-2026-39043

Heap buffer overflow in Matroska demuxer

3 месяца назад
ubuntu логотип
CVE-2026-3902

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) to a single version with underscores. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2026-39020

(An issue in WIngs3D v.2.4.1 allows a local attacker to cause a denial ...)

CVSS3: 5.5
0%
Низкий
4 дня назад
ubuntu логотип
CVE-2026-38978

transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths.

CVSS3: 5.3
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-38974

Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-38969

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

2 месяца назад
ubuntu логотип
CVE-2026-38968

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.

CVSS3: 9.8
1%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-3890

[hcd-ohci: infinite loop]

5 месяцев назад
ubuntu логотип
CVE-2026-3889

Spoofing issue in Thunderbird. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2026-3888

Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.

CVSS3: 7.8
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2026-3886

[virtio-gpu: fix overflow check when allocating 2d image]

2 месяца назад
ubuntu логотип
CVE-2026-3884

Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that allows a creation of more than 1 alert for each 'target' element. An attacker would need to set an arbitrary key-value pair on Object.prototype through a crafted URL achieving a prototype pollution first, before being able to execute arbitrary JavaScript in the context of the user's browser.

CVSS3: 6.1
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2026-38822

In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.

CVSS3: 7.6
1%
Низкий
17 дней назад
ubuntu логотип
CVE-2026-38821

A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.

CVSS3: 7.1
0%
Низкий
17 дней назад
ubuntu логотип
CVE-2026-38820

openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.

CVSS3: 8.3
2%
Низкий
17 дней назад
ubuntu логотип
CVE-2026-38819

Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.

CVSS3: 5.3
0%
Низкий
17 дней назад
ubuntu логотип
CVE-2026-38755

A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

CVSS3: 2.9
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу