Лента событий
Стр. 1 из 1058
CVE-2026-20349
2026-08-11
Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
(Cisco)
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
CVSS 8.6
0.9%
CVE-2026-68820
2026-08-11
Windows Ancillary Function Driver for WinSock
(Microsoft)
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
CVSS 7.0
0.3%
CVE-2026-72898
2026-08-11
Metabase
(Metabase)
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.
CVSS 10.0
10.4%
CVE-2026-8037
2026-08-07
LoadMaster
(Progress)
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
CVSS 9.6
99.3%
CVE-2026-63077
2026-08-05
TeamCity
(JetBrains)
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
CVSS 9.8
10.7%
CVE-2026-18556
2026-08-04
N-central
(N-able)
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
CVSS 7.4
0.5%
CVE-2026-34486
2026-08-04
Tomcat
(Apache)
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.
CVSS 7.5
82.9%
CVE-2026-9198
2026-08-04
Langflow
(IBM)
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
CVSS 9.8
17.4%
CVE-2026-18577
2026-08-03
N-central
(N-able)
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.
CVSS 8.1
4.1%
CVE-2026-20316
2026-07-29
Secure Firewall Management Center (FMC)
(Cisco)
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
CVSS 5.3
0.8%
CVE-2025-68686
2026-07-27
FortiOS
(Fortinet)
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
CVSS 5.9
1.3%
CVE-2026-16812
2026-07-27
VeloCloud Orchestrator
(Arista)
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
CVSS 10.0
0.9%
CVE-2026-16232
2026-07-22
SmartConsole
(Check Point)
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
CVSS 9.1
73.3%
CVE-2026-50522
2026-07-22
SharePoint
(Microsoft)
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
CVSS 9.8
77.0%
CVE-2026-60137
2026-07-21
Core
(WordPress)
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
CVSS 5.9
73.1%
CVE-2026-63030
2026-07-21
Core
(WordPress)
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
CVSS 9.8
95.6%
CVE-2026-0770
2026-07-21
Langflow
(Langflow)
Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
CVSS 9.8
56.9%
CVE-2021-27137
2026-07-21
DD-WRT
(DD-WRT)
DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
CVSS 8.1
16.5%
BDU:2026-10695
RU
2026-07-18
VipNet Client из состава ПКЗИ ViPNet 4
(АО «ИнфоТеКС»)
Уязвимость механизма автоматического обновления ПК ViPNet Administrator связана с недостатками обработки относительных путей. Эксплуатация уязвимости может позволить нарушителю, действующему из смежной доверенной сети, нарушить целостность среды функционирования атакуемого узла путем использования специально сформированного пакета обновления, отравляемого из доверенной сети от имени скомпрометированного узла с ролью ЦУС (Центр управления сетью)
CVSS 5.0
CVE-2026-58644
2026-07-16
SharePoint
(Microsoft)
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
CVSS 9.8
6.4%