Национальные уведомления
Национальные уведомления безопасности (Турция)
Управление кибербезопасности (бывший USOM) ежедневно публикует уведомления; идентификаторы CVE встречаются в тексте. Здесь каждое уведомление связано с записями нашей базы: что в KEV, где зрелый эксплойт, с чего начать.
Источник: публичный API уведомлений siberguvenlik.gov.tr; текст уведомления и рекомендации — на странице ведомства. Сопоставление автоматическое по идентификатору CVE; уведомления без идентификатора показаны только заголовком.
уведомлений: 8 039 · связанных записей CVE: 44 599Последнее уведомление: 1 окт. 2026 г. RSSПоказать только записи из национальных уведомлений
TR-26-1233 · 1 окт. 2026 г.
(Anthropic Claude Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-103012Эксплойта нет2 · —Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead
TR-26-1232 · 1 окт. 2026 г.
(ASUS Çoklu Ürün Güvenlik Bildirimi )
Открыть уведомление на сайте ведомства- CVE-2026-13313Эксплойта нет8.9 · —An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass s
- CVE-2026-14157Эксплойта нет9.4 · —Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via
- CVE-2026-93495Эксплойта нет7 · —Improper initialization in an ASUS certain motherboard allows an physically proximate user to read or write arbitrary memory by inserting a
TR-26-1231 · 1 окт. 2026 г.
(Cato Networks SDP Client Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-10726Эксплойта нет6.8 · —Cato Windows SDP Client arbitrary file disclosure due to improper TLS certificate validation
- CVE-2026-10739Эксплойта нет8.5 · —Cato Networks SDP Client for Windows is vulnerable to Local Privilege Escalation
- CVE-2026-103473Эксплойта нет9.2 · —Deno 2.7.0 through 2.9.7 Command Injection via node:child_process
- CVE-2026-103239Эксплойта нет8.6 · —MISP Tag Collection Save Allows Privilege Escalation via Sibling Model Injection
- CVE-2026-103321Эксплойта нет8.3 · —MISP Stored Cross-Site Scripting (XSS) via Unvalidated Event Graph Preview Image
- CVE-2026-103388Эксплойта нет6.2 · —MISP Stored Cross-Site Scripting via JavaScript URL in Galaxy Cluster Source Field
- CVE-2026-103389Эксплойта нет6.2 · —MISP Stored Cross-Site Scripting via Unvalidated Galaxy Icon Field in Correlation Graph
- CVE-2026-101879Эксплойта нет7.1 · —OpenClaw Windows Node before 2026.7.1-3 Missing Authorization
- CVE-2026-101880Эксплойта нет8.7 · —OpenClaw Windows Node before 2026.7.1 Authorization Bypass
- CVE-2026-101881Эксплойта нет7.1 · —OpenClaw Windows Node before 2026.7.1 Denial of Service
- CVE-2026-101882Эксплойта нет8.7 · —OpenClaw Windows Node before 2026.7.1 Remote Code Execution via system.execApprovals.set
- CVE-2026-101883Эксплойта нет5.3 · —OpenClaw Windows Node through 2026.9.4 SSRF via canvas.present
- CVE-2026-101884Эксплойта нет7.7 · —OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment Override
TR-26-1227 · 1 окт. 2026 г.
(Kiteworks Çoklu Bileşen Güvenlik Zafiyeti)
Открыть уведомление на сайте ведомства- CVE-2026-102103Эксплойта нет9.1 · —Kiteworks Email Protection Gateway server-side request forgery
- CVE-2026-102104Эксплойта нет9.1 · —Kiteworks Email Protection Gateway server-side request forgery
- CVE-2026-102105Эксплойта нет9.1 · —Kiteworks Email Protection Gateway server-side request forgery
- CVE-2026-102106Эксплойта нет9.1 · —Kiteworks Email Protection Gateway improper authentication
- CVE-2026-102107Эксплойта нет4.6 · —Kiteworks Core user impersonation in a file-request feature
- CVE-2026-102108Эксплойта нет7.2 · —Kiteworks Email Protection Gateway deserialization of untrusted data
- CVE-2026-102109Эксплойта нет7.1 · —Kiteworks Secure Data Forms SQL injection
- CVE-2026-102111Эксплойта нет4.9 · —Kiteworks Core Improper Validation of Specified Quantity in Input
- CVE-2026-102112Эксплойта нет7.8 · —Kiteworks Core Local Privilege Escalation
- CVE-2026-102113Эксплойта нет7.8 · —Kiteworks Core Local Privilege Escalation
- CVE-2026-102114Эксплойта нет7.2 · —Kiteworks Core OS Command Injection
- CVE-2026-102115Эксплойта нет9.8 · —Kiteworks Core Authentication Bypass in the Password Reset Workflow
- CVE-2026-102116Эксплойта нет7.2 · —Kiteworks Email Protection Gateway Path Traversal
- CVE-2026-102118Эксплойта нет7.8 · —Kiteworks Core before version 9.5.0 is vulnerable to Local Privilege Escalation
- CVE-2026-102120Эксплойта нет8.8 · —Kiteworks Core OS Command Injection
- CVE-2026-102122Эксплойта нет4.3 · —Kiteworks Core Incorrect Authorization
- CVE-2026-102123Эксплойта нет7.4 · —Kiteworks Core Path Traversal
- CVE-2026-102124Эксплойта нет6.5 · —Kiteworks Core Missing Authentication for Critical Function
- CVE-2026-102125Эксплойта нет8.8 · —Kiteworks Core Sandbox Escape
- CVE-2026-102126Эксплойта нет8.1 · —Kiteworks Core Stored Cross-site Scripting (XSS)
TR-26-1226 · 1 окт. 2026 г.
(JetBrains Çoklu Ürün Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-100253Эксплойта нет8.8 · —In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings
- CVE-2026-100254Эксплойта нет8.8 · —In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection
- CVE-2026-100255Эксплойта нет8.1 · —In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
- CVE-2026-100256Эксплойта нет7.8 · —In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects
- CVE-2026-100257Эксплойта нет4.3 · —In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export
- CVE-2026-100258Эксплойта нет4.3 · —In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings
- CVE-2026-100259Эксплойта нет4.3 · —In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access
- CVE-2026-100260Эксплойта нет5.3 · —In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset
- CVE-2026-100261Эксплойта нет5.4 · —In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission
- CVE-2026-100262Эксплойта нет7.6 · —In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notificatio
- CVE-2026-100263Эксплойта нет4.7 · —In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible
- CVE-2026-100264Эксплойта нет2.7 · —In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host
- CVE-2026-100265Эксплойта нет4.8 · —In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation
- CVE-2026-100266Эксплойта нет7.7 · —In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted ad
- CVE-2026-100267Эксплойта нет5.9 · —In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters
- CVE-2026-100268Эксплойта нет7.7 · —In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates
- CVE-2026-100269Эксплойта нет4.3 · —In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed
- CVE-2026-100270Эксплойта нет3.3 · —In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurat
- CVE-2026-100271Эксплойта нет2.7 · —In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from
- CVE-2026-100272Эксплойта нет4.9 · —In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read
- CVE-2026-100273Эксплойта нет8.2 · —In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution
- CVE-2026-100274Эксплойта нет6.5 · —In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template
- CVE-2026-100275Эксплойта нет6.9 · —In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible
- CVE-2026-100276Эксплойта нет5.9 · —In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action
- CVE-2026-100277Эксплойта нет8.9 · —In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
- CVE-2026-100278Эксплойта нет4.9 · —In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments
- CVE-2026-100279Эксплойта нет6.5 · —In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials
- CVE-2026-100280Эксплойта нет3.1 · —In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible
TR-26-1225 · 30 сент. 2026 г.
(Trex Dijital -Trex MES Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-18782Proof of concept9.8 · —SQL Injection in Trex Digital Manufacturing's Trex MES
- CVE-2026-18783Proof of concept8.8 · —Missing Server-Side Authentication on REST API Endpoint in Trex Digital Manufacturing's Trex MES
TR-26-1224 · 30 сент. 2026 г.
(Dolusoft Yazılım - SOPLOG Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-82307Эксплойта нет9.8 · —Multiple Vulnerabilities in Dolusoft Software's SOPLOG
TR-26-1223 · 30 сент. 2026 г.
(Maksisoft Teknoloji - Maksisoft Gym Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-86778Эксплойта нет5.3 · —Username Enumeration in Maksisoft Technology's Maksisoft Gym
TR-26-1222 · 30 сент. 2026 г.
(Hitachi Energy RTU500 Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-8065Proof of concept9.1 · 1%An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticat
- CVE-2026-8066Эксплойта нет9.1 · 1%A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated
TR-26-1221 · 30 сент. 2026 г.
(GitLab CE/EE Güvenlik Bildirimi )
Открыть уведомление на сайте ведомства- CVE-2026-10518Эксплойта нет4.3 · 0%Incorrect Authorization in GitLab
- CVE-2026-4523Эксплойта нет3.7 · 0%Missing Authorization in GitLab
- CVE-2026-84739Эксплойта нет8.7 · 0%Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-8937Эксплойта нет4.3 · 0%Missing Authorization in GitLab
TR-26-1220 · 30 сент. 2026 г.
(WordPress Eklenti Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-100143Эксплойта нет6.5 · 0%FluentCart < 1.6.5 - Unauthenticated Guest Customer Account Takeover via Checkout Email
- CVE-2026-75823Эксплойта нет7.4 · 0%WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via Registration Role Encryption
- CVE-2026-75824Эксплойта нет5.3 · 0%WP User Frontend 2.5.8 - 4.3.11 - Unauthenticated Account Creation with Registration Disabled
- CVE-2026-75873Эксплойта нет9.8 · 0%Zella Theme < 2.6.3 - Unauthenticated Arbitrary File Upload
- CVE-2026-80333Эксплойта нет5.3 · 0%Solace Extra < 1.7.2 - Unauthenticated Non-Published Post Content Disclosure via Preview Routes
- CVE-2026-82127Эксплойта нет3.5 · 0%Schema & Structured Data for WP & AMP < 1.67 - Editor+ Stored XSS via Taxonomy Term Fields
- CVE-2026-83560Эксплойта нет5.3 · 0%New User Approve 3.1.0 - 3.2.9 - Unauthenticated PII Disclosure via Zapier API Key Bypass
- CVE-2026-85001Эксплойта нет6.8 · 0%EmbedPress 4.4.9 - 4.6.6 - Contributor+ Stored XSS via Elementor Widget showTitle Attribute
- CVE-2026-85415Эксплойта нет6.8 · 0%Audio Player Block 1.1.0 - 1.6.2 - Contributor+ Stored XSS via Audio Download URL
- CVE-2026-85573Эксплойта нет8.8 · 0%All in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stored XSS via SVG Upload
- CVE-2026-85576Эксплойта нет4.3 · 0%All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings Update
- CVE-2026-86789Эксплойта нет5.3 · 0%Connections Business Directory <= 10.4.67 - Unauthenticated Non-Public Directory Entry Disclosure via cn-api/v1 REST Routes
- CVE-2026-87777Эксплойта нет6.8 · 0%Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor Widget Attribute
- CVE-2026-88791Эксплойта нет3.4 · 0%Safe Redirect Manager < 2.3.0 - Open Redirect via Wildcard Redirect Rules
- CVE-2026-88797Эксплойта нет7.1 · 0%Vayu X < 1.0.6 - Subscriber+ Arbitrary WordPress.org Plugin Installation and Activation
- CVE-2026-89190Эксплойта нет4.3 · 0%Robin Image Optimizer < 2.0.8 - Subscriber+ Plugin Settings Disclosure via fy_ajax
- CVE-2026-89193Эксплойта нет7.5 · 0%Robin Image Optimizer 2.0.0 - 2.0.7 - Unauthenticated Stored XSS via WebP URL Delivery HTML Parser
- CVE-2026-89294Эксплойта нет7.5 · 1%Simply Schedule Appointments <= 1.6.12.27 - Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter
- CVE-2026-90953Эксплойта нет4.3 · 0%Image Optimizer by Elementor < 1.7.7 - Subscriber+ Attachment Metadata and Site Statistics Disclosure via Discarded REST Permission Callbacks
- CVE-2026-91051Эксплойта нет6.6 · 0%EWWW Image Optimizer 8.6.0 - 8.7.7 - Author+ PHP Object Injection via 'eio_page_settings' Post Meta
- CVE-2026-91072Эксплойта нет4.4 · 0%EWWW Image Optimizer < 8.8.0 - Admin+ WebP File Rename and Deletion via Unrestricted Path in WebP Migration Handler
- CVE-2026-91832Эксплойта нет7.1 · 0%WP Mobile Menu 2.7.4 - 2.8.8 - Stored XSS via CSRF
- CVE-2026-92424Эксплойта нет6.8 · 0%Content Egg < 11.9.0 - Contributor+ Stored XSS via Import Queue
- CVE-2026-92994Эксплойта нет8.8 · 0%Verge3D < 4.13.1 - Unauthenticated Stored XSS via File Storage API
- CVE-2026-93580Эксплойта нет5.3 · 0%InPost for WooCommerce 1.7.5 - 1.9.7 - Unauthenticated Order Status Forgery via Shipment Webhook
- CVE-2026-94274Эксплойта нет5.3 · 0%YayReviews 1.0.4 - 1.4.0 - Unauthenticated Sensitive Data Disclosure via REST API
- CVE-2026-94297Эксплойта нет2.7 · 0%Media Library Organizer 2.0.4 - 2.1.3 - Contributor+ Arbitrary Taxonomy Term Creation
- CVE-2026-96649Эксплойта нет7.2 · 0%Frontend Post Submission Manager Lite <= 1.3.4 - Unauthenticated Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink)
- CVE-2026-96886Эксплойта нет5.3 · 0%Course Booking System < 7.0.9 - Unauthenticated Attendee PII Disclosure via CSV Export
- CVE-2026-97316Эксплойта нет5.8 · 0%Broken Link Notifier 1.3.1 - 2.0.0 - Unauthenticated SSRF via Redirect Bypass
TR-26-1219 · 30 сент. 2026 г.
(Dell Secure Connect Gateway (SCG) Policy Manager Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-73593Эксплойта нет3 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Active Debug Code vulnerability.
- CVE-2026-73594Эксплойта нет6.4 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains an Improper Certificate Val
- CVE-2026-73595Эксплойта нет4.7 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Download of Code Without
- CVE-2026-73596Эксплойта нет3.8 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure De
- CVE-2026-73597Эксплойта нет6.5 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross-Site Request Forgery (CSRF) vulnerability.
- CVE-2026-73598Эксплойта нет7.8 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignment for Critical Res
- CVE-2026-73599Эксплойта нет5.4 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an URL Redirection to Untrusted Site ('Open Redirec
- CVE-2026-76114Эксплойта нет5.9 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cleartext Transmission of Sensitive Information v
- CVE-2026-35189Эксплойта нет5.3 · 0%Excessive Memory Allocation in Relative CRLDP Processing
- CVE-2026-35191Эксплойта нет3.7 · 0%QUIC Unvalidated Amplification Credit may be Over Accounted
- CVE-2026-42772Эксплойта нет5.3 · 0%Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC
- CVE-2026-54873Эксплойта нет7.5 · 0%QUIC STREAM Fragment Metadata DoS
- CVE-2026-54875Эксплойта нет3.7 · 0%Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V
- CVE-2026-72897Эксплойта нет7.5 · 0%Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake
- CVE-2026-75804Эксплойта нет5.3 · 0%QUIC Connection-Level Flow Control is Not Enforced for Streams
- CVE-2026-75805Эксплойта нет5.3 · 0%NULL Pointer Dereference in CMP Client Revocation Response Handling
- CVE-2026-84783Эксплойта нет7.5 · 0%Use-After-Free in X.509 Extension Cache Under Concurrent Use
- CVE-2026-84784Эксплойта нет7.5 · 0%QUIC: Unbounded RETIRE_CONNECTION_ID Backlog
TR-26-1217 · 30 сент. 2026 г.
(Wikimedia Foundation MediaWiki Güvenlik Zafiyeti)
Открыть уведомление на сайте ведомства- CVE-2026-100240Эксплойта нет— · 0%TemplateSandbox does not check read permissions for the page being previewed
- CVE-2026-100241Эксплойта нет7.5 · 0%Private change tags exposed to anonymous users via revision-tags-change events
- CVE-2026-103046Эксплойта нет6.1 · 0%WikifunctionsFragmentRenderer does unsafe string replacements on user-provided HTML
TR-26-1216 · 30 сент. 2026 г.
(HPE Çoklu Ürün Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-76718Эксплойта нет8.2 · 0%HPE OneView - Cross-site scripting vulnerability
- CVE-2026-76719Эксплойта нет8.2 · 0%HPE OneView - Cross-site scripting vulnerability
- CVE-2026-76720Эксплойта нет4.3 · 0%HPE OneView - URL Redirect vulnerability
- CVE-2026-76721Эксплойта нет9.8 · 1%Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution in HPE Networking Instant ON APs
- CVE-2026-76722Эксплойта нет9.8 · 1%Uncontrolled Format String Vulnerabilities lead to Remote Code Execution or Denial-of-Service in HPE Networking Instant ON APs
- CVE-2026-76723Эксплойта нет9.6 · 0%Unauthenticated Adjacent Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking Instant ON APS
- CVE-2026-76724Эксплойта нет9.6 · 1%Unauthenticated Adjacent Command Injection Vulnerability in HPE Networking Instant ON APs Command Line Interface (CLI) Accessed by the PAPI Protocol
- CVE-2026-76725Эксплойта нет9.6 · 0%Authentication Bypass in a Management Protocol of HPE Networking Instant ON APs
- CVE-2026-76726Эксплойта нет8.1 · 0%Authentication Bypass Leading to Unauthorized Network Access in HPE Networking Instant ON API Endpoint
- CVE-2026-76727Эксплойта нет7.2 · 1%Authenticated Command Injection Vulnerabilities in HPE Networking Instant ON
- CVE-2026-76728Эксплойта нет7.2 · 1%Authenticated Server-Side Request Forgery Leading to Remote Code Execution in HPE Networking Instant ON APs
- CVE-2026-76729Эксплойта нет6.6 · 0%Authenticated Format String Vulnerability allows Memory Corruption in HPE Networking Instant ON API Endpoint
- CVE-2026-76730Эксплойта нет6.5 · 0%Improper PAPI Packet handling leads to unauthorized access in HPE Networking Instant ON APs
- CVE-2026-76731Эксплойта нет6.5 · 0%Authentication Bypass in the Captive Portal of HPE Networking Instant On
- CVE-2026-76732Эксплойта нет6.4 · 0%Authenticated Local Privilege Escalation Vulnerability in a Daemon of HPE Networking Instant ON
- CVE-2026-76733Эксплойта нет4.9 · 0%Authenticated Denial-of-Service Vulnerability in HPE Networking Instant On API Endpoint
- CVE-2026-76734Эксплойта нет4.8 · 0%Unauthenticated Memory Corruption Vulnerability leads to Denial-of-Service in HPE Networking Instant On
- CVE-2026-76735Эксплойта нет4.1 · 0%Authenticated Local Sensitive Information Disclosure in HPE Networking Instant On
- CVE-2026-76736Эксплойта нет3.3 · 0%Authenticated Local Buffer Overflow Vulnerability leads to Denial-of-Service in HPE Networking Instant On
- CVE-2026-76737Эксплойта нет3 · 0%Authenticated Local Path Traversal Vulnerability Leads to Denial-of-Service in HPE Networking Instant On
- CVE-2026-76738Эксплойта нет2.7 · 0%Authenticated Buffer Overflow Vulnerability in the API Endpoint of HPE Networking Instant On Causes Denial-of-Service
TR-26-1215 · 30 сент. 2026 г.
(Mozilla Firefox Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-100756Эксплойта нет8.1 · 0%Incorrect boundary conditions in the Audio/Video: Playback component
- CVE-2026-100757Эксплойта нет8.8 · 0%Use-after-free in the Widget component
- CVE-2026-100758Эксплойта нет9.6 · 0%Sandbox escape in the DOM: Navigation component
- CVE-2026-100759Эксплойта нет— · 0%Uninitialized memory in the Storage: Quota Manager component
- CVE-2026-100760Эксплойта нет— · 0%Sandbox escape in the Security: Process Sandboxing component
- CVE-2026-100761Эксплойта нет8.8 · 0%Privilege escalation due to use-after-free in the Graphics: WebGPU component
- CVE-2026-100762Эксплойта нет9.6 · 0%Sandbox escape due to use-after-free in the DOM: Content Processes component
- CVE-2026-100763Эксплойта нет— · 0%Incorrect boundary conditions in the Graphics: WebGPU component
- CVE-2026-100764Эксплойта нет8.8 · 0%Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component
- CVE-2026-100765Эксплойта нет8.8 · 0%Use-after-free in the JavaScript: WebAssembly component
- CVE-2026-100766Эксплойта нет4.3 · 0%Information disclosure in the Networking: JAR component
- CVE-2026-100767Эксплойта нет8.8 · 0%Use-after-free in the Networking: Cache component
- CVE-2026-100768Эксплойта нет8.8 · 0%Use-after-free in the Graphics: WebGPU component
- CVE-2026-100769Эксплойта нет8.8 · 0%Use-after-free in the JavaScript: WebAssembly component
- CVE-2026-100770Эксплойта нет9.6 · 0%Sandbox escape due to use-after-free in the DOM: Content Processes component
- CVE-2026-100771Эксплойта нет— · 0%Undefined behavior in the DOM: Streams component
- CVE-2026-100772Эксплойта нет8.8 · 0%Use-after-free in the DOM: Core & HTML component
- CVE-2026-100773Эксплойта нет8.8 · 0%Use-after-free in the Storage: IndexedDB component
- CVE-2026-100774Эксплойта нет8.8 · 0%Use-after-free in the DOM: Core & HTML component
- CVE-2026-100775Эксплойта нет— · 0%Sandbox escape in the Graphics component
- CVE-2026-100776Эксплойта нет8.8 · 0%Use-after-free in the JavaScript: WebAssembly component
- CVE-2026-100777Эксплойта нет8.8 · 0%Use-after-free in the Graphics: Canvas2D component
- CVE-2026-100778Эксплойта нет9.6 · 0%Sandbox escape due to use-after-free in the DOM: Core & HTML component
- CVE-2026-100779Эксплойта нет8.8 · 0%Use-after-free in the XSLT component
- CVE-2026-100780Эксплойта нет8.8 · 0%Use-after-free in the DOM: Core & HTML component
- CVE-2026-100781Эксплойта нет— · 0%Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component
- CVE-2026-100782Эксплойта нет8.8 · 0%Privilege escalation due to incorrect boundary conditions in the Graphics component
- CVE-2026-100783Эксплойта нет4.3 · 0%Uninitialized memory in the Audio/Video component
- CVE-2026-100784Эксплойта нет8.8 · 0%Use-after-free in the Layout: Text and Fonts component
- CVE-2026-100785Эксплойта нет8.8 · 0%Use-after-free in the DOM: Core & HTML component
- CVE-2026-100786Эксплойта нет9.6 · 0%Sandbox escape due to use-after-free in the Graphics component
- CVE-2026-100787Эксплойта нет— · 0%Sandbox escape in the XUL component
- CVE-2026-100788Эксплойта нет— · 0%Invalid pointer in the JavaScript: WebAssembly component
- CVE-2026-100789Эксплойта нет8.8 · 0%Use-after-free in the Graphics: Canvas2D component
- CVE-2026-100790Эксплойта нет8.8 · 0%Use-after-free in the XSLT component
- CVE-2026-100791Эксплойта нет8.8 · 0%Use-after-free in the DOM: Core & HTML component
- CVE-2026-100792Эксплойта нет— · 0%JIT miscompilation in the JavaScript: WebAssembly component
- CVE-2026-100793Эксплойта нет— · 0%JIT miscompilation in the JavaScript Engine component
- CVE-2026-100794Эксплойта нет— · 0%Sandbox escape due to incorrect boundary conditions in the Internationalization component
- CVE-2026-100795Эксплойта нет6.5 · 0%Denial-of-service in the Networking component
- CVE-2026-100796Эксплойта нет8.8 · 0%Use-after-free in the JavaScript: WebAssembly component
- CVE-2026-100797Эксплойта нет8.8 · 0%Privilege escalation due to use-after-free in the Graphics: WebRender component
- CVE-2026-100798Эксплойта нет— · 0%Cryptography misuse in Storage: Quota Manager component
- CVE-2026-100799Эксплойта нет4.3 · 0%Uninitialized memory in the Graphics: WebGPU component
- CVE-2026-100800Эксплойта нет9.6 · 0%Sandbox escape due to use-after-free in the Disability Access APIs component
- CVE-2026-100801Эксплойта нет8.8 · 0%Privilege escalation in the DLL Services component
- CVE-2026-100802Эксплойта нет4.3 · 0%Uninitialized memory in the Graphics: WebGPU component
- CVE-2026-100803Эксплойта нет— · 0%Same-origin policy bypass in the WebExtensions component
- CVE-2026-100804Эксплойта нет9.6 · 0%Sandbox escape due to use-after-free in the Preferences: Backend component
- CVE-2026-100805Эксплойта нет7.5 · 0%Race condition, use-after-free in the Audio/Video component
- CVE-2026-100806Эксплойта нет4.3 · 0%Uninitialized memory in the Graphics: WebGPU component
- CVE-2026-100807Эксплойта нет8.8 · 0%Privilege escalation in the DOM: Service Workers component
- CVE-2026-100808Эксплойта нет— · 0%Mitigation bypass in the DOM: Service Workers component
- CVE-2026-100809Эксплойта нет— · 0%Same-origin policy bypass in the DevTools component
- CVE-2026-100810Эксплойта нет— · 0%Other issue in the DevTools component
- CVE-2026-100811Эксплойта нет9.6 · 0%Sandbox escape due to use-after-free in the DOM: Core & HTML component
- CVE-2026-100812Эксплойта нет6.5 · 0%Denial-of-service in the Graphics component
- CVE-2026-100813Эксплойта нет8.8 · 0%Invalid pointer in the JavaScript Engine: JIT component
- CVE-2026-100814Эксплойта нет8.8 · 0%Incorrect boundary conditions in the JavaScript Engine: JIT component
- CVE-2026-100815Эксплойта нет8.8 · 0%Use-after-free in the CSS Parsing and Computation component
- CVE-2026-100816Эксплойта нет— · 0%Site isolation issue in the DOM: Networking component
- CVE-2026-100817Эксплойта нет— · 0%Other issue in the JavaScript: WebAssembly component
- CVE-2026-100818Эксплойта нет9.6 · 0%Sandbox escape due to use-after-free in the Widget: Gtk component
- CVE-2026-100819Эксплойта нет9.6 · 0%Sandbox escape due to incorrect boundary conditions in the XPCOM component
- CVE-2026-100820Эксплойта нет8.8 · 0%Privilege escalation in the Address Bar component
- CVE-2026-100821Эксплойта нет— · 0%Site isolation issue in the Panning and Zooming component
- CVE-2026-100822Эксплойта нет5.4 · 0%Spoofing issue in the Networking: HTTP component
- CVE-2026-100823Эксплойта нет5.4 · 0%Spoofing issue in the Downloads component in Firefox for Android
- CVE-2026-100824Эксплойта нет8.8 · 0%Privilege escalation in the Places component
- CVE-2026-100825Эксплойта нет8.8 · 0%Use-after-free in the JavaScript Engine: JIT component
- CVE-2026-100826Эксплойта нет6.5 · 0%Denial-of-service in the Storage: StorageManager component
- CVE-2026-100828Эксплойта нет— · 0%Mitigation bypass in the Bookmarks & History component
- CVE-2026-100829Эксплойта нет— · 0%Mitigation bypass in the DOM: Security component
- CVE-2026-100830Эксплойта нет— · 0%Mitigation bypass in the DOM: Navigation component
- CVE-2026-100831Эксплойта нет8.8 · 0%Use-after-free in the DOM: UI Events & Focus Handling component
- CVE-2026-100832Эксплойта нет8.8 · 0%Use-after-free in the Graphics: Canvas2D component
- CVE-2026-96869Эксплойта нет4.3 · 0%Information disclosure in the Networking component
- CVE-2026-19547Эксплойта нет7 · 0%Local Privilege Escalation in Ghostscript for Windows
TR-26-1213 · 30 сент. 2026 г.
(Pexip Infinity Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-103100Эксплойта нет7.5 · 0%Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trig
- CVE-2026-103101Эксплойта нет8.6 · 0%Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to
- CVE-2026-103102Эксплойта нет8.6 · 0%Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigge
- CVE-2026-103104Эксплойта нет7.5 · 0%Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a re
TR-26-1212 · 30 сент. 2026 г.
(WatchGuard Fireware OS Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-86134Эксплойта нет8.7 · 0%Fireware OS Pre-Authentication NULL Pointer Dereference Allows Remote Denial of Service
TR-26-1211 · 30 сент. 2026 г.
(Google Chrome Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-95274Эксплойта нет8.3 · 0%Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proc
- CVE-2026-95275Эксплойта нет— · 0%Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy
- CVE-2026-95276Эксплойта нет8.3 · 0%Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proce
- CVE-2026-95277Эксплойта нет9.6 · 0%Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the
- CVE-2026-95278Эксплойта нет— · 0%Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process
- CVE-2026-95279Эксплойта нет5.4 · 0%UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a c
- CVE-2026-95280Эксплойта нет7.5 · 0%Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a cr
- CVE-2026-95281Эксплойта нет9.6 · 0%Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside t
- CVE-2026-95282Эксплойта нет8.8 · 0%Use after free in Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox vi
- CVE-2026-95283Эксплойта нет9.6 · 0%Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary cod
- CVE-2026-95284Эксплойта нет— · 0%Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside t
- CVE-2026-95285Эксплойта нет— · 0%Missing authorization in WebView in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the ren
- CVE-2026-95286Эксплойта нет8.8 · 0%Type confusion in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox vi
- CVE-2026-95287Эксплойта нет5.4 · 0%Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proce
- CVE-2026-95288Эксплойта нет5.4 · 0%UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafte
- CVE-2026-95289Эксплойта нет4.3 · 0%Incorrect authorization in Scroll in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain
- CVE-2026-95290Эксплойта нет5.4 · 0%Missing authorization in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to b
- CVE-2026-95291Эксплойта нет5.4 · 0%UI misrepresentation in SecurityIndicators in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof address bar
- CVE-2026-95292Эксплойта нет4.8 · 0%Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictio
- CVE-2026-95293Эксплойта нет4.7 · 0%Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a cra
- CVE-2026-95294Эксплойта нет5.4 · 0%UI misrepresentation in Browser in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI
- CVE-2026-95295Эксплойта нет4.6 · 0%Information leak in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a local attacker to leak sensitive information via phys
- CVE-2026-95296Эксплойта нет4.3 · 0%Missing authorization in Core in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to o
- CVE-2026-95297Эксплойта нет6.5 · 0%Missing authorization in Contextual Tasks in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via
- CVE-2026-95298Эксплойта нет7.8 · 0%Use after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the
- CVE-2026-95299Эксплойта нет9.6 · 0%Use after free in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a
- CVE-2026-95300Эксплойта нет4.8 · 0%Missing authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass
- CVE-2026-95301Эксплойта нет8.1 · 0%Missing authorization in Extensions in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proce
- CVE-2026-95302Эксплойта нет2.9 · 0%Incorrect authorization in WebAPKs in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to obtain cross-origin dat
- CVE-2026-95303Эксплойта нет— · 0%Incomplete cleanup in SmartCard in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass sy
- CVE-2026-95304Эксплойта нет8.8 · 0%Out of bounds write in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via
- CVE-2026-95305Эксплойта нет4.8 · 0%UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof
- CVE-2026-95306Эксплойта нет8.8 · 0%Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a cr
- CVE-2026-95307Эксплойта нет5.4 · 0%UI misrepresentation in ExtensionsMenu in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to sp
- CVE-2026-95308Эксплойта нет3.4 · 0%Integer overflow in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to po
- CVE-2026-95309Эксплойта нет5.4 · 0%UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafte
- CVE-2026-95310Эксплойта нет9.6 · 0%Use after free in AdFilter in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox v
- CVE-2026-95311Эксплойта нет9.6 · 0%Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentia
- CVE-2026-95312Эксплойта нет3.1 · 0%Information leak in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to
- CVE-2026-95313Эксплойта нет9.6 · 0%Use after free in Fullscreen in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside
- CVE-2026-95314Эксплойта нет— · 0%Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to
- CVE-2026-95315Эксплойта нет7.8 · 0%Use after free in Aura in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sa
- CVE-2026-95316Эксплойта нет2.9 · 0%Unchecked return value in Performance in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially read memory via a loca
- CVE-2026-95317Эксплойта нет3.1 · 0%Incorrect authorization in MediaCapture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to o
- CVE-2026-95318Эксплойта нет9.6 · 0%Buffer overflow in Video in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the
- CVE-2026-95319Эксплойта нет8.3 · 0%Use after free in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to pot
- CVE-2026-95320Эксплойта нет5.4 · 0%Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proce
- CVE-2026-95321Эксплойта нет5.4 · 0%UI misrepresentation in Payments in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a
- CVE-2026-95322Эксплойта нет8.3 · 0%Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer
- CVE-2026-95323Эксплойта нет5.4 · 0%UI misrepresentation in Chromium in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering t
- CVE-2026-95324Эксплойта нет3.4 · 0%Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to
- CVE-2026-95325Эксплойта нет9.6 · 0%Use after free in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the
- CVE-2026-95326Эксплойта нет— · 0%Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass sy
- CVE-2026-95327Эксплойта нет6.5 · 0%Information leak in Networking in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to leak sensitive information via a crafted
- CVE-2026-95328Эксплойта нет6.5 · 0%Confused deputy in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker leveraging social engineering to ob
- CVE-2026-95329Эксплойта нет9.6 · 0%Out of bounds write in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrar
- CVE-2026-95330Эксплойта нет6.5 · 0%Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restriction
- CVE-2026-95331Эксплойта нет9.6 · 0%Out of bounds write in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside
- CVE-2026-95332Эксплойта нет4.7 · 0%Use of uninitialized variable in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to read memory outside
- CVE-2026-95333Эксплойта нет8.1 · 0%Use after free in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox vi
- CVE-2026-95334Эксплойта нет8.3 · 0%Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the rende
- CVE-2026-95335Эксплойта нет8.3 · 0%Use after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentia
- CVE-2026-95336Эксплойта нет6.5 · 0%Information leak in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to
- CVE-2026-95337Эксплойта нет5.4 · 0%UI misrepresentation in Messages in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker leveraging social engineeri
- CVE-2026-95338Эксплойта нет8.8 · 0%Use after free in PDFium in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via
- CVE-2026-95339Эксплойта нет9.6 · 0%Use after free in ServiceWorker in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sand
- CVE-2026-95340Эксплойта нет4.3 · 0%Incorrect authorization in PictureInPicture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering
- CVE-2026-95341Эксплойта нет8.3 · 0%Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proc
- CVE-2026-95342Эксплойта нет4.3 · 0%Missing authorization in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML
- CVE-2026-95343Эксплойта нет8.8 · 0%Use after free in WebAudio in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox vi
- CVE-2026-95344Эксплойта нет8 · 0%Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass site is
- CVE-2026-95345Эксплойта нет8.8 · 0%Use after free in Actor in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a
- CVE-2026-95346Эксплойта нет4.8 · 0%UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via crafted networ
- CVE-2026-95347Эксплойта нет9.6 · 0%Use after free in Updater in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the
- CVE-2026-95348Эксплойта нет8.3 · 0%Use after free in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to po
- CVE-2026-95349Эксплойта нет9.6 · 0%Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary co
- CVE-2026-95350Эксплойта нет9.6 · 0%Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside t
- CVE-2026-95351Эксплойта нет8.3 · 0%Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execut
- CVE-2026-95352Эксплойта нет5.4 · 0%Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypas
- CVE-2026-95353Эксплойта нет8.8 · 0%Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox vi
- CVE-2026-95354Эксплойта нет8.3 · 0%Use after free in Verifier in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to pot
- CVE-2026-95355Эксплойта нет8.3 · 0%Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker who had compromised the re
- CVE-2026-95356Эксплойта нет9.6 · 0%Use after free in WindowDialog in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentiall
- CVE-2026-95357Эксплойта нет9.6 · 0%Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary
- CVE-2026-95358Эксплойта нет4.4 · 0%Incorrect authorization in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to bypass system access res
- CVE-2026-95359Эксплойта нет3.4 · 0%Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the render
- CVE-2026-95360Эксплойта нет5.3 · 0%Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitiv
- CVE-2026-95361Эксплойта нет4.3 · 0%Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web or
- CVE-2026-95362Эксплойта нет8.8 · 0%Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to by
- CVE-2026-95363Эксплойта нет5.4 · 0%UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof
- CVE-2026-95364Эксплойта нет5.4 · 0%Improper input validation in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted
- CVE-2026-95365Эксплойта нет8.8 · 0%Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside t
- CVE-2026-95366Эксплойта нет6.5 · 0%Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process
- CVE-2026-95367Эксплойта нет5.3 · 0%Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process
- CVE-2026-95368Эксплойта нет4.3 · 0%Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to poten
- CVE-2026-95369Эксплойта нет8.8 · 0%Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code
- CVE-2026-95370Эксплойта нет5.4 · 0%Inappropriate implementation in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions v
- CVE-2026-95371Эксплойта нет5.4 · 0%Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer
- CVE-2026-95372Эксплойта нет8.3 · 0%Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to p
- CVE-2026-95373Эксплойта нет8.8 · 0%Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to execute arbitr
- CVE-2026-95374Эксплойта нет— · 0%Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a craft
- CVE-2026-95375Эксплойта нет6.3 · 0%Incorrect authorization in BrowserTag in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer pro
- CVE-2026-95376Эксплойта нет8 · 0%Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineeri
- CVE-2026-95380Эксплойта нет8.8 · 0%Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute
- CVE-2026-95381Эксплойта нет8.3 · 0%Improper input validation in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer pro
- CVE-2026-95382Эксплойта нет6.5 · 0%Improper input validation in Auth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process
- CVE-2026-95384Эксплойта нет5.3 · 0%Race condition in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially leak sensitive info
- CVE-2026-95385Эксплойта нет— · 0%Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveragi
TR-26-1210 · 29 сент. 2026 г.
(Parla Auto - DetaWix Mobile Web Portal Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-86450Эксплойта нет7.5 · 0%Sensitive Data Exposure in Parla Auto's DetaWix Mobile Web Portal
TR-26-1209 · 29 сент. 2026 г.
(Interprobe - Qorela DC Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-87748Эксплойта нет8.8 · 0%Privilege Escalation via Account Takeover in Interprobe's Qorela DC
TR-26-1208 · 29 сент. 2026 г.
(Kubernetes kubectl Güvenlik Zafiyeti)
Открыть уведомление на сайте ведомства- CVE-2026-19444Эксплойта нет6.5 · 0%Kubernetes kubectl cp path traversal on Windows allows arbitrary file writes
- CVE-2026-93355Эксплойта нет7.6 · 0%LiteLLM Weak JWT Authentication via Email-Based User Lookup
TR-26-1206 · 29 сент. 2026 г.
(Canonical LXD Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-85185Эксплойта нет9.6 · 0%Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root
- CVE-2026-85526Эксплойта нет9.9 · 1%Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD
- CVE-2026-86334Эксплойта нет4.2 · 0%CLI Path Traversal via Content-Disposition in LXD Image Export/Copy
- CVE-2026-86335Эксплойта нет6.3 · 0%LXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject Local Reuse
- CVE-2026-87798Эксплойта нет5.8 · 0%LXD client recursive file pull allows directory escape via malicious VM agent
- CVE-2026-87799Эксплойта нет9.9 · 0%Arbitrary file write on LXD host via symlink in migration stream
- CVE-2026-97335Эксплойта нет7.7 · 0%Incorrect authorization in LXD storage volume API allows reading volumes from other projects
- CVE-2026-45562Эксплойта нет7.7 · 0%FreePBX: Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) Module
- CVE-2026-54674Эксплойта нет8.6 · 1%Authenticated Command Injection in FreePBX UCP Interface
- CVE-2026-54675Эксплойта нет8.7 · 1%FreePBX: Authenticated Remote Code Execution via File Upload and Convert in Soundlang Module
- CVE-2026-54708Эксплойта нет8.6 · 0%Authenticated Remote Code Execution via Path Traversal in FreePBX Backup Module
- CVE-2026-54710Эксплойта нет8.6 · 0%FreePBX: Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsafe File Inclusion)
- CVE-2026-75600Эксплойта нет8.6 · 1%FreePBX: Authenticated API generatedocs Host Command Injection
TR-26-1204 · 29 сент. 2026 г.
(Axios HTTP Client Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-101901Эксплойта нет8.2 · 0%Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization
- CVE-2026-101902Эксплойта нет6.9 · 0%Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method
- CVE-2026-101903Эксплойта нет8.2 · 0%Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)
- CVE-2026-101904Эксплойта нет6.9 · 0%Axios: Header Injection via Inherited headers After Minimal Interceptor
- CVE-2026-101905Эксплойта нет7.6 · 0%Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection
- CVE-2026-101906Эксплойта нет8.2 · 0%Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location
- CVE-2026-101907Эксплойта нет7 · 0%Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF
- CVE-2026-101908Эксплойта нет6.9 · 0%Axios: Prototype pollution gadget in fetch adapter can alter outbound requests
- CVE-2026-101909Эксплойта нет8.3 · 0%Axios: Prototype Pollution Gadget in axios toFormData Options
TR-26-1203 · 29 сент. 2026 г.
(Apache Çoklu Ürün Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-82348Эксплойта нет7.7 · 0%Apache Roller: Cross-weblog resource tampering via unscoped authoring lookups
- CVE-2026-82375Эксплойта нет7.4 · 0%Apache Roller: Server-side request forgery via entry trackback and enclosure URLs
- CVE-2026-82376Эксплойта нет7.7 · 0%Apache Roller: XML external entity processing in trackback response parser
- CVE-2026-82377Эксплойта нет9.9 · 1%Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers
- CVE-2026-82378Эксплойта нет9 · 0%Apache Roller: OAuth authorization endpoint trusts request-supplied identity
- CVE-2026-82379Эксплойта нет7.7 · 0%Apache Roller: WSSE digest authentication headers can be replayed
- CVE-2026-82380Эксплойта нет8.1 · 0%Apache Roller: CSRF protection bypass via self-generated salt validation
- CVE-2026-82381Эксплойта нет5.4 · 0%Apache Roller: Stored cross-site scripting in the authoring UI
- CVE-2026-82382Эксплойта нет6.1 · 0%Apache Roller: Reflected cross-site scripting in the frontpage directory parameter
- CVE-2026-82383Эксплойта нет8.2 · 0%Apache Roller: Anonymous setup action allows frontpage configuration tampering
- CVE-2026-82384Proof of concept9.8 · 1%Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint
- CVE-2026-82385Эксплойта нет6.5 · 0%Apache Roller: Weblog template include escapes the Velocity sandbox and reads classpath files
- CVE-2026-82386Эксплойта нет7.7 · 0%Apache Roller: XML external entity processing in OPML bookmark import
- CVE-2026-82387Эксплойта нет5.4 · 0%Apache Roller: Stored cross-site scripting via uploaded media content type
- CVE-2026-82546Эксплойта нет6.1 · 0%Apache Roller: Stored cross-site scripting through incoming Trackback links
- CVE-2026-86507Эксплойта нет6.1 · 0%Apache Roller: Stored XSS in comment moderation via comment author URL
- CVE-2026-91204Эксплойта нет6.1 · 0%Apache Roller: Stored javascript: URI in HTML comments
- CVE-2026-91206Эксплойта нет6.1 · 0%Apache Roller: Reflected XSS in the optional LDAP comment authenticator
- CVE-2026-96740Эксплойта нет6.5 · 0%Streamshub/console: console-operator: streams for apache kafka console: unfiltered kafka client properties → sa-token exfiltration via config.providers
TR-26-1202 · 28 сент. 2026 г.
(Innotim Yazılım - Logsign SIEM Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-90924Эксплойта нет9.8 · 0%Default Admin Credentials in Innotim Software's Logsign SIEM
- CVE-2026-90925Эксплойта нет7.1 · 0%Path Traversal in Innotim Software's Logsign SIEM
- CVE-2026-90926Эксплойта нет8.8 · 0%Code Injection in Innotim Software's Logsign SIEM
TR-26-1201 · 28 сент. 2026 г.
(Iron Mountain - enVision Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-86595Proof of concept8.8 · 0%SQLi in Iron Mountain's enVision
TR-26-1200 · 28 сент. 2026 г.
- Google Chrome ve Microsoft Windows Ayrıntılı Güvenlik Duyurusu (BlueMoon İstismar Zinciri)
Открыть уведомление на сайте ведомства- CVE-2026-85046KEVГотовый эксплойт8.8 · 49%Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a cr
- CVE-2026-85880KEVГотовый эксплойт7.8 · 4%Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
- CVE-2026-87491KEVГотовый эксплойт8.8 · 3%Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via
TR-26-1199 · 28 сент. 2026 г.
(Enocta Eğitim Teknolojileri - Enocta Platform Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-82323Эксплойта нет8.1 · 0%Improper Authorization in Enocta Educational's Enocta Platform
- CVE-2026-82326Эксплойта нет4.1 · 0%HTML Injection in Enocta Educational's Enocta Platform
TR-26-1198 · 28 сент. 2026 г.
(Rolantis Bilgi Teknolojileri - Agentis Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-87752Эксплойта нет6.1 · 0%HTML Injection in Rolantis Information Technologies' Agentis
TR-26-1197 · 28 сент. 2026 г.
(Bimser Çözüm - eBA Plus Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-82915Эксплойта нет6.5 · 0%Path Traversal in Bimser Solution Software's eBA Plus
- CVE-2026-82969Эксплойта нет5.4 · 0%Stored XSS in BİMSER's eBA Plus
- CVE-2026-85134Эксплойта нет8.8 · 0%Arbitrary File Upload Leading to Remote Command Execution in Bimser's eBA Plus
TR-26-1196 · 28 сент. 2026 г.
(Microsoft Outlook Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-100208Эксплойта нет7.5 · 0%Microsoft Office Outlook Remote Code Execution Vulnerability
TR-26-1195 · 28 сент. 2026 г.
(Citrix NetScaler Güvenlik Bildirimi)
Открыть уведомление на сайте ведомства- CVE-2026-88773Эксплойта нет9.3 · 0%HTTP Request Smuggling
- CVE-2026-88775Эксплойта нет8.8 · 0%Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
- CVE-2026-88776Эксплойта нет8.8 · 0%Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
- CVE-2026-88777пока нет в базе
- CVE-2026-88778пока нет в базе
- CVE-2026-100503пока нет в базе
- CVE-2026-100504пока нет в базе
- CVE-2026-100505пока нет в базе
Добавьте продукты в панели, чтобы получать уведомление, когда совпадающая запись попадёт в KEV. →