Búsqueda de CVEs
375.190 resultadosCVE-2026-19518MEDIUMImproper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation.EPSS —CVE-2026-19391MEDIUMInsights-core: insights-core: incomplete credential redaction exposes sssd bind passwords and pacemaker fence credentials in uploaded archivesEPSS —CVE-2026-19517MEDIUMImproper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open SoEPSS —CVE-2026-13716CRITICALPath Traversal: '.../...//' in Crafty ControllerEPSS —CVE-2026-14549—Ray Enterprise Translation <= 1.7.3 - Subscriber+ Language Addition and DeletionEPSS —CVE-2026-14548—Ray Enterprise Translation <= 1.7.3 - Subscriber+ Arbitrary API Token UpdateEPSS —CVE-2026-4757HIGHA VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flEPSS —CVE-2026-12052MEDIUMOut-of-bounds write in USB CDC NCM control handler when host wLength is smaller than the responseEPSS —CVE-2026-6505MEDIUMThe ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. ThEPSS —CVE-2026-5304MEDIUMAn ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be explEPSS —CVE-2026-5303MEDIUMThe ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. ThEPSS —CVE-2026-8158MEDIUMThe Signed Video Framework contained a buffer overflow issue
which could lead the application using this framework to crash. The issue excEPSS —CVE-2026-6181MEDIUMThe Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating withEPSS —CVE-2026-18348MEDIUMVelociraptor NETWORK ACL bypass via upload_azure / upload_sftp / upload_smb VQL pluginsEPSS —CVE-2026-12051MEDIUMNULL pointer dereference in USB DFU device_next download handler (handle_download)EPSS —CVE-2026-19516CRITICALCVE-2026-19516 CVE RecordEPSS —CVE-2026-11894MEDIUMDouble-free / use-after-free in Realtek BEE Bluetooth HCI driver `send()` error pathsEPSS —CVE-2026-11985LOWCross-thread FPU register leak on ARM when FPU enabled without register sharingEPSS —CVE-2026-11893MEDIUMDouble free / use-after-free in Bouffalo Lab HCI driver send() error paths (hci_bflb)EPSS —CVE-2026-16974MEDIUMKirki - Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via post_meta ShortcodeEPSS —