Búsqueda de CVEs

400.802 resultados
CVE-2026-39717MEDIUMWordPress LearnPress plugin <= 4.4.9.1 - Broken Access Control vulnerabilityEPSS —CVE-2026-39601LOWWordPress Booking Calendar plugin <= 11.8.4 - Race Condition vulnerabilityEPSS —CVE-2026-39600MEDIUMWordPress Aculect AI Companion plugin <= 0.8.1 - Unvalidated Redirects and Forwards vulnerabilityEPSS —CVE-2026-39444MEDIUMWordPress PublishPress Series plugin <= 3.1.3 - Insecure Direct Object References (IDOR) vulnerabilityEPSS —CVE-2026-104637MEDIUMonetwothreeneth HospitalManagementSystem controller.php edit_patient unrestricted uploadEPSS —CVE-2026-39439MEDIUMWordPress WebSamurai plugin <= 1.0.7 - Broken Access Control vulnerabilityEPSS —CVE-2026-32585MEDIUMWordPress Airano MCP Bridge plugin <= 2.11.0 - Broken Access Control vulnerabilityEPSS —CVE-2026-32584MEDIUMWordPress Smart One Click Setup – Complete Demo Import &amp; Export plugin <= 1.4.3 - Sensitive Data Exposure vulnerabilityEPSS —CVE-2026-90970CRITICALImproper Neutralization of Special Elements Used in a Template Engine in GitLab AI GatewayEPSS —CVE-2026-104625MEDIUMCodeAstro Simple Loan Management System index.php sql injectionEPSS —CVE-2026-5782MEDIUMReflected XSS in Loglama.NET's TurkHotspotEPSS —CVE-2026-104026HIGHIn Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed EPSS —CVE-2026-104614MEDIUMCodeAstro Simple Pharmacy Management System delete.php sql injectionEPSS —CVE-2026-94422HIGHxdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escapeEPSS —CVE-2026-19652CRITICALDivi Membership <= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id' ParameterEPSS —CVE-2026-93875HIGHJetAppointment <= 2.5.2.1 - Unauthenticated Stored Cross-Site Scripting via 'friendlyTime' ParameterEPSS —CVE-2026-104721MEDIUMLogback: Incomplete protection against CVE-2026-19880EPSS —CVE-2026-104613MEDIUMCodeAstro Simple Pharmacy Management System view.php sql injectionEPSS —CVE-2026-85215HIGHSQL Injection in GG Soft's PaperworkEPSS —CVE-2026-66054MEDIUMApache Thrift: C++ THeaderTransport does not enforce configured maxFrameSizeEPSS —