Национальные уведомления
Национальные уведомления безопасности (Турция)
Управление кибербезопасности (бывший USOM) ежедневно публикует уведомления; идентификаторы CVE встречаются в тексте. Здесь каждое уведомление связано с записями нашей базы: что в KEV, где зрелый эксплойт, с чего начать.
Источник: публичный API уведомлений siberguvenlik.gov.tr; текст уведомления и рекомендации — на странице ведомства. Сопоставление автоматическое по идентификатору CVE; уведомления без идентификатора показаны только заголовком.
уведомлений: 8 051 · связанных записей CVE: 44 675Последнее уведомление: 2 окт. 2026 г. RSSПоказать только записи из национальных уведомлений
TR-26-1245 · 2 окт. 2026 г.
(Loglama.net - TurkHotspot Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-5782Эксплойта нет5.2 · —Reflected XSS in Loglama.NET's TurkHotspot
TR-26-1244 · 2 окт. 2026 г.
(GG Soft Yazılım - Paperwork Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-85215Эксплойта нет7.1 · —SQL Injection in GG Soft's Paperwork
TR-26-1243 · 2 окт. 2026 г.
(Softtr Bilişim - E-Ticaret Paketi Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-11795Эксплойта нет5.3 · —User Enumeration in Softtr's E-Commerce Pack
TR-26-1242 · 2 окт. 2026 г.
(AVEZ Elektronik - LMS Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-85209Эксплойта нет6.5 · —IDOR in AVEZ Electronics's LMS
TR-26-1241 · 2 окт. 2026 г.
(HAVELSAN - Sef - AI Chatbot Platform Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-80298Эксплойта нет8.8 · 0%SQL Injection in HAVELSAN's Sef - AI Chatbot Platform
- CVE-2026-80337Эксплойта нет5.3 · 0%Unauthorized Cross-Chatbot Tool Invocation in HAVELSAN's Sef - AI Chatbot Platform
- CVE-2026-80443Эксплойта нет7.4 · 0%Insecure TLS Certificate Validation in API Tool Runner in HAVELSAN's Sef - AI Chatbot Platform
- CVE-2026-80464Эксплойта нет4.9 · 0%API Tool Runner SSRF in HAVELSAN's Sef - AI Chatbot Platform
TR-26-1240 · 2 окт. 2026 г.
(Wind River VxWorks 7 Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-104018Эксплойта нет8.8 · 1%VxWorks 7 improper privilege management
TR-26-1239 · 2 окт. 2026 г.
(JohnsonControls Çoklu Ürün Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-27873Эксплойта нет5.6 · 0%- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying.
- CVE-2026-34493Эксплойта нет7.2 · 0%- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations.
- CVE-2026-34494Эксплойта нет7.2 · 0%- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations.
- CVE-2026-64892Эксплойта нет6.3 · 0%- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations.
- CVE-2026-64893Эксплойта нет7.3 · 0%- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack.
- CVE-2026-71448Эксплойта нет5.6 · 0%: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse.
- CVE-2026-71449Эксплойта нет9.3 · 0%: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data.
TR-26-1238 · 2 окт. 2026 г.
(WordPress Eklenti Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-10026Эксплойта нет7.2 · 0%CTX Feed Pro <= 7.6.12 - Authenticated (Administrator+) Remote Code Execution
- CVE-2026-101888Эксплойта нет8.6 · 1%Prime Mover < 2.2.1 Zip Slip Path Traversal File Write
- CVE-2026-101889Эксплойта нет7 · 0%Prime Mover < 2.2.1 Path Traversal via wprime-config.json
- CVE-2026-101890Эксплойта нет5.1 · 0%Prime Mover < 2.2.1 Stored XSS via Package Metadata
- CVE-2026-14378Proof of concept9.8 · 0%DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow
- CVE-2026-15896Эксплойта нет9.1 · 1%Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter
- CVE-2026-15897Эксплойта нет8.8 · 0%Super Forms – Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via 'user_id' Parameter in Register & Login
- CVE-2026-15989Proof of concept9.8 · 0%Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter
- CVE-2026-19660Proof of concept9.8 · 0%Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter
- CVE-2026-19807Эксплойта нет8.8 · 0%ByteCoreStack <= 1.2.3 - Authenticated (Subscriber+) Privilege Escalation via wp_update_user_meta MCP Tool
- CVE-2026-19902Эксплойта нет6.1 · 0%Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via {search-query} Dynamic Tag (Referer Header)
- CVE-2026-62071Эксплойта нет9.3 · 0%WordPress WordPress File Upload plugin <= 5.1.10 - SQL Injection vulnerability
- CVE-2026-75957Эксплойта нет9.8 · 1%Ultimate Multisite <= 2.15.0 - Unauthenticated Authentication Bypass via 'checkout_form' Parameter
- CVE-2026-78471Эксплойта нет5.4 · 0%Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name
- CVE-2026-84925Эксплойта нет6.1 · 0%Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Reflected Cross-Site Scripting via 'lang' Parameter
- CVE-2026-89047Эксплойта нет6.1 · 0%Social Media Share Buttons & Social Sharing Icons <= 3.0.1 - Reflected DOM-Based Cross-Site Scripting via URL
- CVE-2026-90438Эксплойта нет7.2 · 0%Ninja Forms <= 3.15.4 - Unauthenticated Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission
- CVE-2026-92144Эксплойта нет7.2 · 1%Forminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter
- CVE-2026-92174Эксплойта нет7.5 · 1%SiteOrigin Widgets Bundle <= 1.73.2 - Authenticated (Contributor+) Local File Inclusion via 'theme' Parameter
- CVE-2026-92820Эксплойта нет8.1 · 1%Ninja Forms - File Uploads <= 3.3.34 - Unauthenticated Arbitrary File Upload
- CVE-2026-93367Эксплойта нет7.2 · 0%Visitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title)
- CVE-2026-93882Эксплойта нет7.5 · 0%LearnPress <= 4.4.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'item_id' Parameter
- CVE-2026-96256Эксплойта нет6.4 · 0%Gutenberg Essential Blocks <= 6.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker' Attribute
TR-26-1237 · 2 окт. 2026 г.
(Apache HTTP Server Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-63686Эксплойта нет7.5 · 0%Apache HTTP Server: mod_xml2enc crash on charset conversion failure
- CVE-2026-63718Эксплойта нет7.5 · 0%Apache HTTP Server: mod_proxy_uwsgi Transfer-Encoding response smuggling
- CVE-2026-73636Эксплойта нет8.1 · 0%Apache HTTP Server: mod_auth_digest one-time-nonce replay attack
- CVE-2026-73637Эксплойта нет7.3 · 0%Apache HTTP Server: mod_auth_digest DoS attack
- CVE-2026-79768Эксплойта нет5.3 · 0%Apache HTTP Server: mod_userdir information disclosure
- CVE-2026-93546Эксплойта нет8.8 · 0%Apache HTTP Server: mod_dav_fs namespace overflow
TR-26-1236 · 2 окт. 2026 г.
(Red Hat Keycloak Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-103884Эксплойта нет6.5 · 0%Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file read
TR-26-1235 · 2 окт. 2026 г.
(cPanel WHM Mass Modify Accounts/Multilang adminbin Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-93029Эксплойта нет9 · 0%There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
- CVE-2026-93697Эксплойта нет9 · 0%There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
- CVE-2026-93698Эксплойта нет9.9 · 0%Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
TR-26-1234 · 2 окт. 2026 г.
(Ghost Platformu Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-103266Эксплойта нет7.1 · 0%Ghost 5.2.0 before 6.62.0 Unauthenticated Stripe Checkout Account Modification
- CVE-2026-103267Эксплойта нет5.3 · 0%Ghost 0.5.0 before 6.62.0 Arbitrary Email Registration via Staff Invite
- CVE-2026-103268Эксплойта нет8.7 · 0%Ghost 1.0.0 before 6.62.0 Suspension Bypass via Password Reset
- CVE-2026-103269Эксплойта нет6.9 · 0%Ghost 5.3.0 before 6.62.0 Missing Authorization via Post Excerpts
- CVE-2026-103271Эксплойта нет8.7 · 0%Ghost 4.0.0 before 6.63.0 Restricted Content Bypass
- CVE-2026-103272Эксплойта нет8.7 · 0%Ghost 2.10.0 before 6.63.0 Staff Enumeration via Content API
- CVE-2026-103273Эксплойта нет5.3 · 0%Ghost 4.3.0 before 6.58.0 Incorrect Authorization via Staff Token
- CVE-2026-103274Эксплойта нет6.9 · 0%Ghost 5.3.0 before 6.58.0 Unauthenticated Comment Read
- CVE-2026-103275Эксплойта нет5.3 · 0%Ghost 5.42.2 before 6.58.0 Password Hash Disclosure
- CVE-2026-103276Эксплойта нет6.9 · 0%Ghost before 6.20.0 File Read via URL Encoding Bypass
- CVE-2026-103277Эксплойта нет8.6 · 0%Ghost 2.5.0 before 6.34.0 Untrusted Script Execution via oEmbed
- CVE-2026-103278Эксплойта нет8.5 · 0%Ghost 5.8.0 before 6.34.0 Staff Account Takeover via Admin iframe
- CVE-2026-103279Эксплойта нет7.6 · 0%Ghost 3.10.0 before 6.34.0 Session Invalidation Bypass
- CVE-2026-103280Эксплойта нет6.9 · 0%Ghost 0.8.0 before 6.23.0 Information Disclosure via Setup Endpoint
- CVE-2026-103281Эксплойта нет5.3 · 0%Ghost 3.23.0 before 6.23.0 API Key Exposure via Admin API
- CVE-2026-103282Эксплойта нет5.3 · 0%Ghost 0.5.0 before 6.23.0 Multiple Account Creation via Invite Token
- CVE-2026-103283Эксплойта нет8.6 · 0%Ghost 6.20.0 before 6.57.1 Authentication Bypass via Session Handling
- CVE-2026-103284Эксплойта нет5.3 · 0%Ghost 5.125.1 before 6.57.1 Information Disclosure via Feedback
- CVE-2026-103285Эксплойта нет5.3 · 0%Ghost 5.19.0 before 6.57.1 Cross-Site Request Forgery
- CVE-2026-103286Эксплойта нет8.5 · 0%Ghost 2.21.0 before 6.56.0 Privilege Escalation via Notifications
- CVE-2026-103287Эксплойта нет5.1 · 0%Ghost 1.18.0 before 6.27.0 Server-Side Request Forgery via Webhook
- CVE-2026-103288Эксплойта нет7.1 · 0%Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comment Like
- CVE-2026-103289Эксплойта нет7.1 · 0%Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comments
- CVE-2026-103290Эксплойта нет5.1 · 0%Ghost 6.14.0 before 6.27.0 Path Traversal via ImageSize
- CVE-2026-103291Эксплойта нет5.3 · 0%Ghost 3.20.2 before 6.51.0 SSRF via image-size fetch
- CVE-2026-103292Эксплойта нет8.6 · 0%Ghost 0.5.3 before 6.50.0 Cross-Site Scripting via ghost_head
- CVE-2026-70590Эксплойта нет4.8 · 0%Ghost: Blind Password Hash Disclosure in Ghost Admin API
TR-26-1233 · 1 окт. 2026 г.
(Anthropic Claude Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-103012Эксплойта нет2 · 0%Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead
TR-26-1232 · 1 окт. 2026 г.
(ASUS Çoklu Ürün Güvenlik Bildirimi )
Открыть уведомление на сайте ведомства- CVE-2026-13313Эксплойта нет8.9 · 1%An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass s
- CVE-2026-14157Эксплойта нет9.4 · 1%Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via
- CVE-2026-93495Эксплойта нет7 · 0%Improper initialization in an ASUS certain motherboard allows an physically proximate user to read or write arbitrary memory by inserting a
TR-26-1231 · 1 окт. 2026 г.
(Cato Networks SDP Client Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-10726Эксплойта нет6.8 · 0%Cato Windows SDP Client arbitrary file disclosure due to improper TLS certificate validation
- CVE-2026-10739Эксплойта нет8.5 · 0%Cato Networks SDP Client for Windows is vulnerable to Local Privilege Escalation
- CVE-2026-103473Эксплойта нет9.2 · 1%Deno 2.7.0 through 2.9.7 Command Injection via node:child_process
- CVE-2026-103239Эксплойта нет8.6 · 0%MISP Tag Collection Save Allows Privilege Escalation via Sibling Model Injection
- CVE-2026-103321Эксплойта нет8.3 · 0%MISP Stored Cross-Site Scripting (XSS) via Unvalidated Event Graph Preview Image
- CVE-2026-103388Эксплойта нет6.2 · 0%MISP Stored Cross-Site Scripting via JavaScript URL in Galaxy Cluster Source Field
- CVE-2026-103389Эксплойта нет6.2 · 0%MISP Stored Cross-Site Scripting via Unvalidated Galaxy Icon Field in Correlation Graph
- CVE-2026-101879Эксплойта нет7.1 · 0%OpenClaw Windows Node before 2026.7.1-3 Missing Authorization
- CVE-2026-101880Эксплойта нет8.7 · 1%OpenClaw Windows Node before 2026.7.1 Authorization Bypass
- CVE-2026-101881Эксплойта нет7.1 · 0%OpenClaw Windows Node before 2026.7.1 Denial of Service
- CVE-2026-101882Эксплойта нет8.7 · 1%OpenClaw Windows Node before 2026.7.1 Remote Code Execution via system.execApprovals.set
- CVE-2026-101883Эксплойта нет5.3 · 0%OpenClaw Windows Node through 2026.9.4 SSRF via canvas.present
- CVE-2026-101884Эксплойта нет7.7 · 0%OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment Override
TR-26-1227 · 1 окт. 2026 г.
(Kiteworks Çoklu Bileşen Güvenlik Zafiyeti)
Открыть уведомление на сайте ведомства- CVE-2026-102103Эксплойта нет9.1 · 0%Kiteworks Email Protection Gateway server-side request forgery
- CVE-2026-102104Эксплойта нет9.1 · 0%Kiteworks Email Protection Gateway server-side request forgery
- CVE-2026-102105Эксплойта нет9.1 · 0%Kiteworks Email Protection Gateway server-side request forgery
- CVE-2026-102106Эксплойта нет9.1 · 0%Kiteworks Email Protection Gateway improper authentication
- CVE-2026-102107Эксплойта нет4.6 · 0%Kiteworks Core user impersonation in a file-request feature
- CVE-2026-102108Эксплойта нет7.2 · 0%Kiteworks Email Protection Gateway deserialization of untrusted data
- CVE-2026-102109Эксплойта нет7.1 · 0%Kiteworks Secure Data Forms SQL injection
- CVE-2026-102111Эксплойта нет4.9 · 0%Kiteworks Core Improper Validation of Specified Quantity in Input
- CVE-2026-102112Эксплойта нет7.8 · 0%Kiteworks Core Local Privilege Escalation
- CVE-2026-102113Эксплойта нет7.8 · 0%Kiteworks Core Local Privilege Escalation
- CVE-2026-102114Эксплойта нет7.2 · 1%Kiteworks Core OS Command Injection
- CVE-2026-102115Эксплойта нет9.8 · 0%Kiteworks Core Authentication Bypass in the Password Reset Workflow
- CVE-2026-102116Эксплойта нет7.2 · 1%Kiteworks Email Protection Gateway Path Traversal
- CVE-2026-102118Эксплойта нет7.8 · 0%Kiteworks Core before version 9.5.0 is vulnerable to Local Privilege Escalation
- CVE-2026-102120Эксплойта нет8.8 · 0%Kiteworks Core OS Command Injection
- CVE-2026-102122Эксплойта нет4.3 · 0%Kiteworks Core Incorrect Authorization
- CVE-2026-102123Эксплойта нет7.4 · 0%Kiteworks Core Path Traversal
- CVE-2026-102124Эксплойта нет6.5 · 0%Kiteworks Core Missing Authentication for Critical Function
- CVE-2026-102125Эксплойта нет8.8 · 0%Kiteworks Core Sandbox Escape
- CVE-2026-102126Эксплойта нет8.1 · 0%Kiteworks Core Stored Cross-site Scripting (XSS)
TR-26-1226 · 1 окт. 2026 г.
(JetBrains Çoklu Ürün Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-100253Эксплойта нет8.8 · 0%In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings
- CVE-2026-100254Эксплойта нет8.8 · 0%In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection
- CVE-2026-100255Эксплойта нет9.8 · 0%In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
- CVE-2026-100256Эксплойта нет7.8 · 0%In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects
- CVE-2026-100257Эксплойта нет4.3 · 0%In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export
- CVE-2026-100258Эксплойта нет4.3 · 1%In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings
- CVE-2026-100259Эксплойта нет4.3 · 0%In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access
- CVE-2026-100260Эксплойта нет5.3 · 0%In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset
- CVE-2026-100261Эксплойта нет5.4 · 0%In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission
- CVE-2026-100262Эксплойта нет7.1 · 0%In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notificatio
- CVE-2026-100263Эксплойта нет6.1 · 0%In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible
- CVE-2026-100264Эксплойта нет2.7 · 0%In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host
- CVE-2026-100265Эксплойта нет6.5 · 0%In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation
- CVE-2026-100266Эксплойта нет6.5 · 0%In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted ad
- CVE-2026-100267Эксплойта нет5.9 · 0%In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters
- CVE-2026-100268Эксплойта нет2.7 · 0%In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates
- CVE-2026-100269Эксплойта нет4.3 · 0%In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed
- CVE-2026-100270Эксплойта нет2.7 · 0%In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurat
- CVE-2026-100271Эксплойта нет2.7 · 0%In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from
- CVE-2026-100272Эксплойта нет4.9 · 0%In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read
- CVE-2026-100273Эксплойта нет9.8 · 0%In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution
- CVE-2026-100274Эксплойта нет6.5 · 1%In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template
- CVE-2026-100275Эксплойта нет4.8 · 0%In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible
- CVE-2026-100276Эксплойта нет7.5 · 0%In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action
- CVE-2026-100277Эксплойта нет9.8 · 0%In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
- CVE-2026-100278Эксплойта нет4.9 · 0%In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments
- CVE-2026-100279Эксплойта нет6.5 · 0%In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials
- CVE-2026-100280Эксплойта нет4.3 · 0%In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible
TR-26-1225 · 30 сент. 2026 г.
(Trex Dijital -Trex MES Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-18782Proof of concept9.8 · 0%SQL Injection in Trex Digital Manufacturing's Trex MES
- CVE-2026-18783Proof of concept8.8 · 0%Missing Server-Side Authentication on REST API Endpoint in Trex Digital Manufacturing's Trex MES
TR-26-1224 · 30 сент. 2026 г.
(Dolusoft Yazılım - SOPLOG Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-82307Эксплойта нет9.8 · 0%Multiple Vulnerabilities in Dolusoft Software's SOPLOG
TR-26-1223 · 30 сент. 2026 г.
(Maksisoft Teknoloji - Maksisoft Gym Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-86778Эксплойта нет5.3 · 0%Username Enumeration in Maksisoft Technology's Maksisoft Gym
TR-26-1222 · 30 сент. 2026 г.
(Hitachi Energy RTU500 Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-8065Proof of concept9.1 · 1%An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticat
- CVE-2026-8066Эксплойта нет9.1 · 1%A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated
TR-26-1221 · 30 сент. 2026 г.
(GitLab CE/EE Güvenlik Bildirimi )
Открыть уведомление на сайте ведомства- CVE-2026-10518Эксплойта нет4.3 · 0%Incorrect Authorization in GitLab
- CVE-2026-4523Эксплойта нет3.7 · 0%Missing Authorization in GitLab
- CVE-2026-84739Эксплойта нет8.7 · 0%Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-8937Эксплойта нет4.3 · 0%Missing Authorization in GitLab
TR-26-1220 · 30 сент. 2026 г.
(WordPress Eklenti Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-100143Эксплойта нет6.5 · 0%FluentCart < 1.6.5 - Unauthenticated Guest Customer Account Takeover via Checkout Email
- CVE-2026-75823Эксплойта нет7.4 · 0%WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via Registration Role Encryption
- CVE-2026-75824Эксплойта нет5.3 · 0%WP User Frontend 2.5.8 - 4.3.11 - Unauthenticated Account Creation with Registration Disabled
- CVE-2026-75873Эксплойта нет9.8 · 1%Zella Theme < 2.6.3 - Unauthenticated Arbitrary File Upload
- CVE-2026-80333Эксплойта нет5.3 · 0%Solace Extra < 1.7.2 - Unauthenticated Non-Published Post Content Disclosure via Preview Routes
- CVE-2026-82127Эксплойта нет3.5 · 0%Schema & Structured Data for WP & AMP < 1.67 - Editor+ Stored XSS via Taxonomy Term Fields
- CVE-2026-83560Эксплойта нет5.3 · 0%New User Approve 3.1.0 - 3.2.9 - Unauthenticated PII Disclosure via Zapier API Key Bypass
- CVE-2026-85001Эксплойта нет6.8 · 0%EmbedPress 4.4.9 - 4.6.6 - Contributor+ Stored XSS via Elementor Widget showTitle Attribute
- CVE-2026-85415Эксплойта нет6.8 · 0%Audio Player Block 1.1.0 - 1.6.2 - Contributor+ Stored XSS via Audio Download URL
- CVE-2026-85573Эксплойта нет8.8 · 0%All in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stored XSS via SVG Upload
- CVE-2026-85576Эксплойта нет4.3 · 0%All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings Update
- CVE-2026-86789Эксплойта нет5.3 · 0%Connections Business Directory <= 10.4.67 - Unauthenticated Non-Public Directory Entry Disclosure via cn-api/v1 REST Routes
- CVE-2026-87777Эксплойта нет6.8 · 0%Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor Widget Attribute
- CVE-2026-88791Эксплойта нет3.4 · 0%Safe Redirect Manager < 2.3.0 - Open Redirect via Wildcard Redirect Rules
- CVE-2026-88797Эксплойта нет7.1 · 0%Vayu X < 1.0.6 - Subscriber+ Arbitrary WordPress.org Plugin Installation and Activation
- CVE-2026-89190Эксплойта нет4.3 · 0%Robin Image Optimizer < 2.0.8 - Subscriber+ Plugin Settings Disclosure via fy_ajax
- CVE-2026-89193Эксплойта нет7.5 · 0%Robin Image Optimizer 2.0.0 - 2.0.7 - Unauthenticated Stored XSS via WebP URL Delivery HTML Parser
- CVE-2026-89294Эксплойта нет7.5 · 1%Simply Schedule Appointments <= 1.6.12.27 - Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter
- CVE-2026-90953Эксплойта нет4.3 · 0%Image Optimizer by Elementor < 1.7.7 - Subscriber+ Attachment Metadata and Site Statistics Disclosure via Discarded REST Permission Callbacks
- CVE-2026-91051Эксплойта нет6.6 · 0%EWWW Image Optimizer 8.6.0 - 8.7.7 - Author+ PHP Object Injection via 'eio_page_settings' Post Meta
- CVE-2026-91072Эксплойта нет4.4 · 0%EWWW Image Optimizer < 8.8.0 - Admin+ WebP File Rename and Deletion via Unrestricted Path in WebP Migration Handler
- CVE-2026-91832Эксплойта нет7.1 · 0%WP Mobile Menu 2.7.4 - 2.8.8 - Stored XSS via CSRF
- CVE-2026-92424Эксплойта нет6.8 · 0%Content Egg < 11.9.0 - Contributor+ Stored XSS via Import Queue
- CVE-2026-92994Эксплойта нет8.8 · 0%Verge3D < 4.13.1 - Unauthenticated Stored XSS via File Storage API
- CVE-2026-93580Эксплойта нет5.3 · 0%InPost for WooCommerce 1.7.5 - 1.9.7 - Unauthenticated Order Status Forgery via Shipment Webhook
- CVE-2026-94274Эксплойта нет5.3 · 0%YayReviews 1.0.4 - 1.4.0 - Unauthenticated Sensitive Data Disclosure via REST API
- CVE-2026-94297Эксплойта нет2.7 · 0%Media Library Organizer 2.0.4 - 2.1.3 - Contributor+ Arbitrary Taxonomy Term Creation
- CVE-2026-96649Эксплойта нет7.2 · 0%Frontend Post Submission Manager Lite <= 1.3.4 - Unauthenticated Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink)
- CVE-2026-96886Эксплойта нет5.3 · 0%Course Booking System < 7.0.9 - Unauthenticated Attendee PII Disclosure via CSV Export
- CVE-2026-97316Эксплойта нет5.8 · 0%Broken Link Notifier 1.3.1 - 2.0.0 - Unauthenticated SSRF via Redirect Bypass
TR-26-1219 · 30 сент. 2026 г.
(Dell Secure Connect Gateway (SCG) Policy Manager Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-73593Эксплойта нет3 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Active Debug Code vulnerability.
- CVE-2026-73594Эксплойта нет6.4 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains an Improper Certificate Val
- CVE-2026-73595Эксплойта нет4.7 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Download of Code Without
- CVE-2026-73596Эксплойта нет3.8 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure De
- CVE-2026-73597Эксплойта нет6.5 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross-Site Request Forgery (CSRF) vulnerability.
- CVE-2026-73598Эксплойта нет7.8 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignment for Critical Res
- CVE-2026-73599Эксплойта нет5.4 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an URL Redirection to Untrusted Site ('Open Redirec
- CVE-2026-76114Эксплойта нет5.9 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cleartext Transmission of Sensitive Information v
- CVE-2026-35189Эксплойта нет5.3 · 0%Excessive Memory Allocation in Relative CRLDP Processing
- CVE-2026-35191Эксплойта нет3.7 · 0%QUIC Unvalidated Amplification Credit may be Over Accounted
- CVE-2026-42772Эксплойта нет5.3 · 0%Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC
- CVE-2026-54873Эксплойта нет7.5 · 0%QUIC STREAM Fragment Metadata DoS
- CVE-2026-54875Эксплойта нет3.7 · 0%Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V
- CVE-2026-72897Эксплойта нет7.5 · 0%Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake
- CVE-2026-75804Эксплойта нет5.3 · 0%QUIC Connection-Level Flow Control is Not Enforced for Streams
- CVE-2026-75805Эксплойта нет5.3 · 0%NULL Pointer Dereference in CMP Client Revocation Response Handling
- CVE-2026-84783Эксплойта нет7.5 · 0%Use-After-Free in X.509 Extension Cache Under Concurrent Use
- CVE-2026-84784Эксплойта нет7.5 · 0%QUIC: Unbounded RETIRE_CONNECTION_ID Backlog
TR-26-1217 · 30 сент. 2026 г.
(Wikimedia Foundation MediaWiki Güvenlik Zafiyeti)
Открыть уведомление на сайте ведомства- CVE-2026-100240Эксплойта нет9.1 · 0%TemplateSandbox does not check read permissions for the page being previewed
- CVE-2026-100241Эксплойта нет7.5 · 0%Private change tags exposed to anonymous users via revision-tags-change events
- CVE-2026-103046Эксплойта нет6.1 · 0%WikifunctionsFragmentRenderer does unsafe string replacements on user-provided HTML
TR-26-1216 · 30 сент. 2026 г.
(HPE Çoklu Ürün Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-76718Эксплойта нет8.2 · 0%HPE OneView - Cross-site scripting vulnerability
- CVE-2026-76719Эксплойта нет8.2 · 0%HPE OneView - Cross-site scripting vulnerability
- CVE-2026-76720Эксплойта нет4.3 · 0%HPE OneView - URL Redirect vulnerability
- CVE-2026-76721Эксплойта нет9.8 · 1%Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution in HPE Networking Instant ON APs
- CVE-2026-76722Эксплойта нет9.8 · 1%Uncontrolled Format String Vulnerabilities lead to Remote Code Execution or Denial-of-Service in HPE Networking Instant ON APs
- CVE-2026-76723Эксплойта нет9.6 · 0%Unauthenticated Adjacent Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking Instant ON APS
- CVE-2026-76724Эксплойта нет9.6 · 1%Unauthenticated Adjacent Command Injection Vulnerability in HPE Networking Instant ON APs Command Line Interface (CLI) Accessed by the PAPI Protocol
- CVE-2026-76725Эксплойта нет9.6 · 0%Authentication Bypass in a Management Protocol of HPE Networking Instant ON APs
- CVE-2026-76726Эксплойта нет8.1 · 0%Authentication Bypass Leading to Unauthorized Network Access in HPE Networking Instant ON API Endpoint
- CVE-2026-76727Эксплойта нет7.2 · 1%Authenticated Command Injection Vulnerabilities in HPE Networking Instant ON
- CVE-2026-76728Эксплойта нет7.2 · 1%Authenticated Server-Side Request Forgery Leading to Remote Code Execution in HPE Networking Instant ON APs
- CVE-2026-76729Эксплойта нет6.6 · 0%Authenticated Format String Vulnerability allows Memory Corruption in HPE Networking Instant ON API Endpoint
- CVE-2026-76730Эксплойта нет6.5 · 0%Improper PAPI Packet handling leads to unauthorized access in HPE Networking Instant ON APs
- CVE-2026-76731Эксплойта нет6.5 · 0%Authentication Bypass in the Captive Portal of HPE Networking Instant On
- CVE-2026-76732Эксплойта нет6.4 · 0%Authenticated Local Privilege Escalation Vulnerability in a Daemon of HPE Networking Instant ON
- CVE-2026-76733Эксплойта нет4.9 · 0%Authenticated Denial-of-Service Vulnerability in HPE Networking Instant On API Endpoint
- CVE-2026-76734Эксплойта нет4.8 · 0%Unauthenticated Memory Corruption Vulnerability leads to Denial-of-Service in HPE Networking Instant On
- CVE-2026-76735Эксплойта нет4.1 · 0%Authenticated Local Sensitive Information Disclosure in HPE Networking Instant On
- CVE-2026-76736Эксплойта нет3.3 · 0%Authenticated Local Buffer Overflow Vulnerability leads to Denial-of-Service in HPE Networking Instant On
- CVE-2026-76737Эксплойта нет3 · 0%Authenticated Local Path Traversal Vulnerability Leads to Denial-of-Service in HPE Networking Instant On
- CVE-2026-76738Эксплойта нет2.7 · 0%Authenticated Buffer Overflow Vulnerability in the API Endpoint of HPE Networking Instant On Causes Denial-of-Service
TR-26-1215 · 30 сент. 2026 г.
(Mozilla Firefox Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-100756Эксплойта нет8.1 · 0%Incorrect boundary conditions in the Audio/Video: Playback component
- CVE-2026-100757Эксплойта нет8.8 · 0%Use-after-free in the Widget component
- CVE-2026-100758Эксплойта нет9.6 · 0%Sandbox escape in the DOM: Navigation component
- CVE-2026-100759Эксплойта нет8.1 · 0%Uninitialized memory in the Storage: Quota Manager component
- CVE-2026-100760Эксплойта нет9.6 · 0%Sandbox escape in the Security: Process Sandboxing component
- CVE-2026-100761Эксплойта нет8.8 · 0%Privilege escalation due to use-after-free in the Graphics: WebGPU component
- CVE-2026-100762Эксплойта нет9.6 · 0%Sandbox escape due to use-after-free in the DOM: Content Processes component
- CVE-2026-100763Эксплойта нет9.1 · 0%Incorrect boundary conditions in the Graphics: WebGPU component
- CVE-2026-100764Эксплойта нет8.8 · 0%Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component
- CVE-2026-100765Эксплойта нет8.8 · 0%Use-after-free in the JavaScript: WebAssembly component
- CVE-2026-100766Эксплойта нет4.3 · 0%Information disclosure in the Networking: JAR component
- CVE-2026-100767Эксплойта нет8.8 · 0%Use-after-free in the Networking: Cache component
- CVE-2026-100768Эксплойта нет8.8 · 0%Use-after-free in the Graphics: WebGPU component
- CVE-2026-100769Эксплойта нет8.8 · 0%Use-after-free in the JavaScript: WebAssembly component
- CVE-2026-100770Эксплойта нет9.6 · 0%Sandbox escape due to use-after-free in the DOM: Content Processes component
- CVE-2026-100771Эксплойта нет8.1 · 0%Undefined behavior in the DOM: Streams component
- CVE-2026-100772Эксплойта нет8.8 · 0%Use-after-free in the DOM: Core & HTML component
- CVE-2026-100773Эксплойта нет8.8 · 0%Use-after-free in the Storage: IndexedDB component
- CVE-2026-100774Эксплойта нет8.8 · 0%Use-after-free in the DOM: Core & HTML component
- CVE-2026-100775Эксплойта нет9.6 · 0%Sandbox escape in the Graphics component
- CVE-2026-100776Эксплойта нет8.8 · 0%Use-after-free in the JavaScript: WebAssembly component
- CVE-2026-100777Эксплойта нет8.8 · 0%Use-after-free in the Graphics: Canvas2D component
- CVE-2026-100778Эксплойта нет9.6 · 0%Sandbox escape due to use-after-free in the DOM: Core & HTML component
- CVE-2026-100779Эксплойта нет8.8 · 0%Use-after-free in the XSLT component
- CVE-2026-100780Эксплойта нет8.8 · 0%Use-after-free in the DOM: Core & HTML component
- CVE-2026-100781Эксплойта нет9.6 · 0%Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component
- CVE-2026-100782Эксплойта нет8.8 · 0%Privilege escalation due to incorrect boundary conditions in the Graphics component
- CVE-2026-100783Эксплойта нет4.3 · 0%Uninitialized memory in the Audio/Video component
- CVE-2026-100784Эксплойта нет8.8 · 0%Use-after-free in the Layout: Text and Fonts component
- CVE-2026-100785Эксплойта нет8.8 · 0%Use-after-free in the DOM: Core & HTML component
- CVE-2026-100786Эксплойта нет9.6 · 0%Sandbox escape due to use-after-free in the Graphics component
- CVE-2026-100787Эксплойта нет9.6 · 0%Sandbox escape in the XUL component
- CVE-2026-100788Эксплойта нет9.8 · 0%Invalid pointer in the JavaScript: WebAssembly component
- CVE-2026-100789Эксплойта нет8.8 · 0%Use-after-free in the Graphics: Canvas2D component
- CVE-2026-100790Эксплойта нет8.8 · 0%Use-after-free in the XSLT component
- CVE-2026-100791Эксплойта нет8.8 · 0%Use-after-free in the DOM: Core & HTML component
- CVE-2026-100792Эксплойта нет7.1 · 0%JIT miscompilation in the JavaScript: WebAssembly component
- CVE-2026-100793Эксплойта нет6.5 · 0%JIT miscompilation in the JavaScript Engine component
- CVE-2026-100794Эксплойта нет9.6 · 0%Sandbox escape due to incorrect boundary conditions in the Internationalization component
- CVE-2026-100795Эксплойта нет6.5 · 0%Denial-of-service in the Networking component
- CVE-2026-100796Эксплойта нет8.8 · 0%Use-after-free in the JavaScript: WebAssembly component
- CVE-2026-100797Эксплойта нет8.8 · 0%Privilege escalation due to use-after-free in the Graphics: WebRender component
- CVE-2026-100798Эксплойта нет8.1 · 0%Cryptography misuse in Storage: Quota Manager component
- CVE-2026-100799Эксплойта нет4.3 · 0%Uninitialized memory in the Graphics: WebGPU component
- CVE-2026-100800Эксплойта нет9.6 · 0%Sandbox escape due to use-after-free in the Disability Access APIs component
- CVE-2026-100801Эксплойта нет8.8 · 0%Privilege escalation in the DLL Services component
- CVE-2026-100802Эксплойта нет4.3 · 0%Uninitialized memory in the Graphics: WebGPU component
- CVE-2026-100803Эксплойта нет8.1 · 0%Same-origin policy bypass in the WebExtensions component
- CVE-2026-100804Эксплойта нет9.6 · 0%Sandbox escape due to use-after-free in the Preferences: Backend component
- CVE-2026-100805Эксплойта нет7.5 · 0%Race condition, use-after-free in the Audio/Video component
- CVE-2026-100806Эксплойта нет4.3 · 0%Uninitialized memory in the Graphics: WebGPU component
- CVE-2026-100807Эксплойта нет8.8 · 0%Privilege escalation in the DOM: Service Workers component
- CVE-2026-100808Эксплойта нет8.8 · 0%Mitigation bypass in the DOM: Service Workers component
- CVE-2026-100809Эксплойта нет8.1 · 0%Same-origin policy bypass in the DevTools component
- CVE-2026-100810Эксплойта нет9.8 · 0%Other issue in the DevTools component
- CVE-2026-100811Эксплойта нет9.6 · 0%Sandbox escape due to use-after-free in the DOM: Core & HTML component
- CVE-2026-100812Эксплойта нет6.5 · 0%Denial-of-service in the Graphics component
- CVE-2026-100813Эксплойта нет8.8 · 0%Invalid pointer in the JavaScript Engine: JIT component
- CVE-2026-100814Эксплойта нет8.8 · 0%Incorrect boundary conditions in the JavaScript Engine: JIT component
- CVE-2026-100815Эксплойта нет8.8 · 0%Use-after-free in the CSS Parsing and Computation component
- CVE-2026-100816Эксплойта нет8.1 · 0%Site isolation issue in the DOM: Networking component
- CVE-2026-100817Эксплойта нет5.4 · 0%Other issue in the JavaScript: WebAssembly component
- CVE-2026-100818Эксплойта нет9.6 · 0%Sandbox escape due to use-after-free in the Widget: Gtk component
- CVE-2026-100819Эксплойта нет9.6 · 0%Sandbox escape due to incorrect boundary conditions in the XPCOM component
- CVE-2026-100820Эксплойта нет8.8 · 0%Privilege escalation in the Address Bar component
- CVE-2026-100821Эксплойта нет4.7 · 0%Site isolation issue in the Panning and Zooming component
- CVE-2026-100822Эксплойта нет5.4 · 0%Spoofing issue in the Networking: HTTP component
- CVE-2026-100823Эксплойта нет5.4 · 0%Spoofing issue in the Downloads component in Firefox for Android
- CVE-2026-100824Эксплойта нет8.8 · 0%Privilege escalation in the Places component
- CVE-2026-100825Эксплойта нет8.8 · 0%Use-after-free in the JavaScript Engine: JIT component
- CVE-2026-100826Эксплойта нет6.5 · 0%Denial-of-service in the Storage: StorageManager component
- CVE-2026-100828Эксплойта нет9.6 · 0%Mitigation bypass in the Bookmarks & History component
- CVE-2026-100829Эксплойта нет9.6 · 0%Mitigation bypass in the DOM: Security component
- CVE-2026-100830Эксплойта нет8.1 · 0%Mitigation bypass in the DOM: Navigation component
- CVE-2026-100831Эксплойта нет8.8 · 0%Use-after-free in the DOM: UI Events & Focus Handling component
- CVE-2026-100832Эксплойта нет8.8 · 0%Use-after-free in the Graphics: Canvas2D component
- CVE-2026-96869Эксплойта нет4.3 · 0%Information disclosure in the Networking component
- CVE-2026-19547Эксплойта нет7 · 0%Local Privilege Escalation in Ghostscript for Windows
TR-26-1213 · 30 сент. 2026 г.
(Pexip Infinity Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-103100Эксплойта нет7.5 · 0%Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trig
- CVE-2026-103101Эксплойта нет8.6 · 0%Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to
- CVE-2026-103102Эксплойта нет8.6 · 0%Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigge
- CVE-2026-103104Эксплойта нет7.5 · 0%Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a re
TR-26-1212 · 30 сент. 2026 г.
(WatchGuard Fireware OS Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-86134Эксплойта нет8.7 · 0%Fireware OS Pre-Authentication NULL Pointer Dereference Allows Remote Denial of Service
TR-26-1211 · 30 сент. 2026 г.
(Google Chrome Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-95274Эксплойта нет8.3 · 0%Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proc
- CVE-2026-95275Эксплойта нет6.5 · 0%Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy
- CVE-2026-95276Эксплойта нет8.3 · 0%Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proce
- CVE-2026-95277Эксплойта нет9.6 · 0%Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the
- CVE-2026-95278Эксплойта нет8.4 · 0%Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process
- CVE-2026-95279Эксплойта нет5.4 · 0%UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a c
- CVE-2026-95280Эксплойта нет7.5 · 0%Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a cr
- CVE-2026-95281Эксплойта нет9.6 · 1%Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside t
- CVE-2026-95282Эксплойта нет8.8 · 0%Use after free in Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox vi
- CVE-2026-95283Эксплойта нет9.6 · 1%Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary cod
- CVE-2026-95284Эксплойта нет9.6 · 1%Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside t
- CVE-2026-95285Эксплойта нет8.4 · 0%Missing authorization in WebView in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the ren
- CVE-2026-95286Эксплойта нет8.8 · 0%Type confusion in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox vi
- CVE-2026-95287Эксплойта нет5.4 · 0%Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proce
- CVE-2026-95288Эксплойта нет5.4 · 0%UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafte
- CVE-2026-95289Эксплойта нет4.3 · 0%Incorrect authorization in Scroll in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain
- CVE-2026-95290Эксплойта нет5.4 · 0%Missing authorization in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to b
- CVE-2026-95291Эксплойта нет5.4 · 0%UI misrepresentation in SecurityIndicators in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof address bar
- CVE-2026-95292Эксплойта нет4.8 · 0%Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictio
- CVE-2026-95293Эксплойта нет4.7 · 0%Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a cra
- CVE-2026-95294Эксплойта нет5.4 · 0%UI misrepresentation in Browser in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI
- CVE-2026-95295Эксплойта нет4.6 · 0%Information leak in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a local attacker to leak sensitive information via phys
- CVE-2026-95296Эксплойта нет4.3 · 0%Missing authorization in Core in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to o
- CVE-2026-95297Эксплойта нет6.5 · 0%Missing authorization in Contextual Tasks in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via
- CVE-2026-95298Эксплойта нет7.8 · 0%Use after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the
- CVE-2026-95299Эксплойта нет9.6 · 0%Use after free in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a
- CVE-2026-95300Эксплойта нет4.8 · 0%Missing authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass
- CVE-2026-95301Эксплойта нет8.1 · 0%Missing authorization in Extensions in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proce
- CVE-2026-95302Эксплойта нет2.9 · 0%Incorrect authorization in WebAPKs in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to obtain cross-origin dat
- CVE-2026-95303Эксплойта нет6.5 · 0%Incomplete cleanup in SmartCard in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass sy
- CVE-2026-95304Эксплойта нет8.8 · 0%Out of bounds write in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via
- CVE-2026-95305Эксплойта нет4.8 · 0%UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof
- CVE-2026-95306Эксплойта нет8.8 · 0%Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a cr
- CVE-2026-95307Эксплойта нет5.4 · 0%UI misrepresentation in ExtensionsMenu in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to sp
- CVE-2026-95308Эксплойта нет3.4 · 0%Integer overflow in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to po
- CVE-2026-95309Эксплойта нет5.4 · 0%UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafte
- CVE-2026-95310Эксплойта нет9.6 · 0%Use after free in AdFilter in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox v
- CVE-2026-95311Эксплойта нет9.6 · 0%Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentia
- CVE-2026-95312Эксплойта нет3.1 · 0%Information leak in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to
- CVE-2026-95313Эксплойта нет9.6 · 0%Use after free in Fullscreen in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside
- CVE-2026-95314Эксплойта нет8.1 · 0%Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to
- CVE-2026-95315Эксплойта нет7.8 · 0%Use after free in Aura in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sa
- CVE-2026-95316Эксплойта нет2.9 · 0%Unchecked return value in Performance in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially read memory via a loca
- CVE-2026-95317Эксплойта нет3.1 · 0%Incorrect authorization in MediaCapture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to o
- CVE-2026-95318Эксплойта нет9.6 · 1%Buffer overflow in Video in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the
- CVE-2026-95319Эксплойта нет8.3 · 0%Use after free in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to pot
- CVE-2026-95320Эксплойта нет5.4 · 0%Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proce
- CVE-2026-95321Эксплойта нет5.4 · 0%UI misrepresentation in Payments in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a
- CVE-2026-95322Эксплойта нет8.3 · 0%Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer
- CVE-2026-95323Эксплойта нет5.4 · 0%UI misrepresentation in Chromium in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering t
- CVE-2026-95324Эксплойта нет3.4 · 0%Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to
- CVE-2026-95325Эксплойта нет9.6 · 0%Use after free in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the
- CVE-2026-95326Эксплойта нет8.4 · 0%Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass sy
- CVE-2026-95327Эксплойта нет6.5 · 0%Information leak in Networking in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to leak sensitive information via a crafted
- CVE-2026-95328Эксплойта нет6.5 · 0%Confused deputy in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker leveraging social engineering to ob
- CVE-2026-95329Эксплойта нет9.6 · 0%Out of bounds write in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrar
- CVE-2026-95330Эксплойта нет6.5 · 0%Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restriction
- CVE-2026-95331Эксплойта нет9.6 · 0%Out of bounds write in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside
- CVE-2026-95332Эксплойта нет4.7 · 0%Use of uninitialized variable in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to read memory outside
- CVE-2026-95333Эксплойта нет8.1 · 0%Use after free in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox vi
- CVE-2026-95334Эксплойта нет8.3 · 0%Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the rende
- CVE-2026-95335Эксплойта нет8.3 · 0%Use after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentia
- CVE-2026-95336Эксплойта нет6.5 · 0%Information leak in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to
- CVE-2026-95337Эксплойта нет5.4 · 0%UI misrepresentation in Messages in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker leveraging social engineeri
- CVE-2026-95338Эксплойта нет8.8 · 0%Use after free in PDFium in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via
- CVE-2026-95339Эксплойта нет9.6 · 0%Use after free in ServiceWorker in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sand
- CVE-2026-95340Эксплойта нет4.3 · 0%Incorrect authorization in PictureInPicture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering
- CVE-2026-95341Эксплойта нет8.3 · 0%Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proc
- CVE-2026-95342Эксплойта нет4.3 · 0%Missing authorization in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML
- CVE-2026-95343Эксплойта нет8.8 · 1%Use after free in WebAudio in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox vi
- CVE-2026-95344Эксплойта нет8 · 0%Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass site is
- CVE-2026-95345Эксплойта нет8.8 · 0%Use after free in Actor in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a
- CVE-2026-95346Эксплойта нет4.8 · 0%UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via crafted networ
- CVE-2026-95347Эксплойта нет9.6 · 0%Use after free in Updater in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the
- CVE-2026-95348Эксплойта нет8.3 · 0%Use after free in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to po
- CVE-2026-95349Эксплойта нет9.6 · 1%Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary co
- CVE-2026-95350Эксплойта нет9.6 · 1%Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside t
- CVE-2026-95351Эксплойта нет8.3 · 0%Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execut
- CVE-2026-95352Эксплойта нет5.4 · 0%Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypas
- CVE-2026-95353Эксплойта нет8.8 · 0%Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox vi
- CVE-2026-95354Эксплойта нет8.3 · 0%Use after free in Verifier in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to pot
- CVE-2026-95355Эксплойта нет8.3 · 0%Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker who had compromised the re
- CVE-2026-95356Эксплойта нет9.6 · 0%Use after free in WindowDialog in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentiall
- CVE-2026-95357Эксплойта нет9.6 · 0%Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary
- CVE-2026-95358Эксплойта нет4.4 · 0%Incorrect authorization in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to bypass system access res
- CVE-2026-95359Эксплойта нет3.4 · 0%Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the render
- CVE-2026-95360Эксплойта нет5.3 · 0%Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitiv
- CVE-2026-95361Эксплойта нет4.3 · 0%Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web or
- CVE-2026-95362Эксплойта нет8.8 · 0%Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to by
- CVE-2026-95363Эксплойта нет5.4 · 0%UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof
- CVE-2026-95364Эксплойта нет5.4 · 0%Improper input validation in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted
- CVE-2026-95365Эксплойта нет8.8 · 0%Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside t
- CVE-2026-95366Эксплойта нет6.5 · 0%Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process
- CVE-2026-95367Эксплойта нет5.3 · 0%Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process
- CVE-2026-95368пока нет в базе
- CVE-2026-95369пока нет в базе
- CVE-2026-95370пока нет в базе
- CVE-2026-95371пока нет в базе
- CVE-2026-95372пока нет в базе
- CVE-2026-95373пока нет в базе
- CVE-2026-95374пока нет в базе
- CVE-2026-95375пока нет в базе
- CVE-2026-95376пока нет в базе
- CVE-2026-95380пока нет в базе
- CVE-2026-95381пока нет в базе
- CVE-2026-95382пока нет в базе
- CVE-2026-95384пока нет в базе
- CVE-2026-95385пока нет в базе
TR-26-1210 · 29 сент. 2026 г.
(Parla Auto - DetaWix Mobile Web Portal Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-86450пока нет в базе
TR-26-1209 · 29 сент. 2026 г.
(Interprobe - Qorela DC Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-87748пока нет в базе
TR-26-1208 · 29 сент. 2026 г.
(Kubernetes kubectl Güvenlik Zafiyeti)
Открыть уведомление на сайте ведомства- CVE-2026-19444пока нет в базе
- CVE-2026-93355пока нет в базе
TR-26-1206 · 29 сент. 2026 г.
(Canonical LXD Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-85185пока нет в базе
- CVE-2026-85526пока нет в базе
- CVE-2026-86334пока нет в базе
- CVE-2026-86335пока нет в базе
- CVE-2026-87798пока нет в базе
- CVE-2026-87799пока нет в базе
- CVE-2026-97335пока нет в базе
Добавьте продукты в панели, чтобы получать уведомление, когда совпадающая запись попадёт в KEV. →