Búsqueda de CVEs

375.190 resultados
CVE-2026-19518MEDIUMImproper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation.EPSS CVE-2026-19391MEDIUMInsights-core: insights-core: incomplete credential redaction exposes sssd bind passwords and pacemaker fence credentials in uploaded archivesEPSS CVE-2026-19517MEDIUMImproper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open SoEPSS CVE-2026-13716CRITICALPath Traversal: '.../...//' in Crafty ControllerEPSS CVE-2026-14549Ray Enterprise Translation <= 1.7.3 - Subscriber+ Language Addition and DeletionEPSS CVE-2026-14548Ray Enterprise Translation <= 1.7.3 - Subscriber+ Arbitrary API Token UpdateEPSS CVE-2026-4757HIGHA VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flEPSS CVE-2026-12052MEDIUMOut-of-bounds write in USB CDC NCM control handler when host wLength is smaller than the responseEPSS CVE-2026-6505MEDIUMThe ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. ThEPSS CVE-2026-5304MEDIUMAn ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be explEPSS CVE-2026-5303MEDIUMThe ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. ThEPSS CVE-2026-8158MEDIUMThe Signed Video Framework contained a  buffer overflow issue which could lead the application using this framework to crash. The issue excEPSS CVE-2026-6181MEDIUMThe Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating withEPSS CVE-2026-18348MEDIUMVelociraptor NETWORK ACL bypass via upload_azure / upload_sftp / upload_smb VQL pluginsEPSS CVE-2026-12051MEDIUMNULL pointer dereference in USB DFU device_next download handler (handle_download)EPSS CVE-2026-19516CRITICALCVE-2026-19516 CVE RecordEPSS CVE-2026-11894MEDIUMDouble-free / use-after-free in Realtek BEE Bluetooth HCI driver `send()` error pathsEPSS CVE-2026-11985LOWCross-thread FPU register leak on ARM when FPU enabled without register sharingEPSS CVE-2026-11893MEDIUMDouble free / use-after-free in Bouffalo Lab HCI driver send() error paths (hci_bflb)EPSS CVE-2026-16974MEDIUMKirki - Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via post_meta ShortcodeEPSS