CVE-2026-26081 HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.
Information published.
EPSS 0.00 CVE-2026-26081 HAProxy US
Information published.
EPSS 0.00 CVE-2026-26081 HAProxy US
Information published.
EPSS 0.01 CVE-2026-26080 HAProxy US
Information published.
EPSS 0.00 CVE-2026-63308 US
Information published.
EPSS 0.00 CVE-2026-50243 US
Information published.
EPSS 0.00 CVE-2026-41637 US
Information published.
EPSS 0.00 CVE-2026-50252 US
Information published.
EPSS 0.00 CVE-2026-50251 US
Information published.
EPSS 0.00 CVE-2026-55991 libngtcp2 US
Information published.
EPSS 0.00 CVE-2026-55990 Unbound US
Information published.
EPSS 0.00 CVE-2026-50046 US
Information published.
EPSS 0.00 CVE-2026-14586 US
Information published.
EPSS 0.00 CVE-2026-46582 US
Information published.
EPSS 0.00 CVE-2026-54478 US
Information published.
EPSS 0.00 CVE-2026-56444 US
Information published.
EPSS 0.00 CVE-2026-32665 US
Information published.
EPSS 0.00 CVE-2026-40691 US
Information published.
EPSS 0.00 CVE-2026-55717 US
Information published.
EPSS 0.00 CVE-2026-44621 Libunbound US
Information published.
EPSS 0.00 CVE-2026-56416 US
Information published.
EPSS 0.00 CVE-2026-52863 US
Information published.
EPSS 0.00 CVE-2026-55708 US
Information published.
EPSS 0.00 CVE-2026-44690 US
Information published.
EPSS 0.00 CVE-2026-50248 US
Information published.
EPSS 0.00 CVE-2026-50045 US
Information published.
EPSS 0.00 CVE-2026-44687 US
Information published.
EPSS 0.00 CVE-2026-55973 US
Information published.
EPSS 0.00 CVE-2026-53910 GNU US PL 2 zdrojů
Information published.
EPSS 0.00 CVE-2026-62994 US
Information published.
EPSS 0.00 CVE-2026-63136 Elasticsearch US
Information published.
EPSS 0.00 CVE-2026-63263 Elasticsearch US
Information published.
EPSS 0.00 CVE-2026-63140 Elasticsearch US
Information published.
EPSS 0.00 CVE-2026-56145 Elasticsearch US
Information published.
EPSS 0.00 CVE-2026-39879 syslog-ng US
Information published.
EPSS 0.00 CVE-2026-26199 US
Information published.
EPSS 0.00 CVE-2026-26197 US
CISA added CVE-2026-50522 to the Known Exploited Vulnerabilities catalog. Affected product: Microsoft SharePoint. Remediation due date: 2026-07-25.
KEV ✓ EPSS 0.85 CVSS 8.1 CVE-2026-50522 Microsoft veřejná správa US 3 zdrojů
Information published.
EPSS 0.00 CVE-2026-42770 US
Information published.
EPSS 0.00 CVE-2026-38752 BusyBox US
Information published.
EPSS 0.00 CVE-2026-38753 Busybox US
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-50325.
EPSS 0.00 CVSS 7.0 CVE-2026-50325 Microsoft US 2 zdrojů
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-50297.
EPSS 0.00 CVSS 7.0 CVE-2026-50297 Microsoft US 2 zdrojů
Information published.
Information published.
EPSS 0.00 CVE-2026-56434 NGINX US
Information published.
EPSS 0.04 CVE-2026-42533 NGINX US
Information published.
EPSS 0.00 CVE-2026-38755 BusyBox US
Information published.
EPSS 0.00 CVE-2026-38754 Busybox US
Information published.
EPSS 0.00 CVE-2026-59884 pyasn1 US
Information published.
EPSS 0.00 CVE-2026-60081 US
Information published.
EPSS 0.00 CVE-2026-15392 US
Information published.
EPSS 0.00 CVE-2026-60082 US
Information published.
EPSS 0.00 CVE-2026-15043 DBI::SQL::Nano US
Information published.
EPSS 0.00 CVE-2026-57433 US
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-56171 US
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58598 US
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-59117 US
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-58643 US
Information published.
EPSS 0.00 CVE-2026-59831 GitHub US
Information published.
EPSS 0.00 CVE-2026-42505 US
Information published.
EPSS 0.00 CVE-2026-39822 US
Information published.
EPSS 0.00 CVE-2026-13221 Perl US