Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 116

Количество 116

rocky логотип

RLSA-2026:35828

24 дня назад

Important: grafana security update

EPSS: Низкий
rocky логотип

RLSA-2026:35827

24 дня назад

Important: grafana security update

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2285-1

около 2 месяцев назад

Security update for yq

EPSS: Низкий
rocky логотип

RLSA-2026:34359

26 дней назад

Important: opentelemetry-collector security update

EPSS: Низкий
rocky логотип

RLSA-2026:34357

24 дня назад

Important: opentelemetry-collector security update

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20892-1

около 2 месяцев назад

Security update for yq

EPSS: Низкий
ubuntu логотип

CVE-2026-25681

2 месяца назад

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2026-25681

2 месяца назад

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-25681

2 месяца назад

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2026-25681

2 месяца назад

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2026-25681

2 месяца назад

Parsing arbitrary HTML which is then rendered using Render can result ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2026-39821

2 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 9.6
EPSS: Низкий
redhat логотип

CVE-2026-39821

2 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2026-39821

2 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 9.6
EPSS: Низкий
msrc логотип

CVE-2026-39821

2 месяца назад

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

CVSS3: 10
EPSS: Низкий
debian логотип

CVE-2026-39821

2 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encode ...

CVSS3: 9.6
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21120-1

около 1 месяца назад

Security update for mcphost

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20956-1

около 2 месяцев назад

Security update for trivy

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3203-1

8 дней назад

Security update for kubevirt

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2733-1

28 дней назад

Security update for buildah

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:35828

Important: grafana security update

24 дня назад
rocky логотип
RLSA-2026:35827

Important: grafana security update

24 дня назад
suse-cvrf логотип
SUSE-SU-2026:2285-1

Security update for yq

около 2 месяцев назад
rocky логотип
RLSA-2026:34359

Important: opentelemetry-collector security update

26 дней назад
rocky логотип
RLSA-2026:34357

Important: opentelemetry-collector security update

24 дня назад
suse-cvrf логотип
openSUSE-SU-2026:20892-1

Security update for yq

около 2 месяцев назад
ubuntu логотип
CVE-2026-25681

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

CVSS3: 6.1
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-25681

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

CVSS3: 8.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-25681

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

CVSS3: 6.1
0%
Низкий
2 месяца назад
msrc логотип
CVE-2026-25681

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

CVSS3: 6.1
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-25681

Parsing arbitrary HTML which is then rendered using Render can result ...

CVSS3: 6.1
0%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 9.6
1%
Низкий
2 месяца назад
redhat логотип
CVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 8.2
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 9.6
1%
Низкий
2 месяца назад
msrc логотип
CVE-2026-39821

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

CVSS3: 10
1%
Низкий
2 месяца назад
debian логотип
CVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encode ...

CVSS3: 9.6
1%
Низкий
2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21120-1

Security update for mcphost

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20956-1

Security update for trivy

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:3203-1

Security update for kubevirt

8 дней назад
suse-cvrf логотип
SUSE-SU-2026:2733-1

Security update for buildah

28 дней назад

Уязвимостей на страницу