Búsqueda de CVEs
400.928 resultadosCVE-2026-59669MEDIUMMultiple vulnerabilities in the Repasat applicationEPSS 0.3%CVE-2026-91784MEDIUMArgument Injection leading to arbitrary process termination in gotopEPSS 0.2%CVE-2026-18036HIGHNTRU leaks private key information by reducing secret values with a non-constant-time integer divisionEPSS 0.3%CVE-2026-97637CRITICALJSON API Auth <= 3.1.2 - Unauthenticated Authentication Bypass via Cached 'generate_auth_cookie' ResponseEPSS 0.6%CVE-2026-94432MEDIUMAppointment Booking Plugin <= 5.7.1 - Insecure Direct Object Reference to Unauthenticated Unauthorized Transaction Intent Creation/Modification and Invoice Enumeration via 'invoice_id' ParameterEPSS 0.3%CVE-2026-97338MEDIUMDownload Manager <= 3.3.70 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Display NameEPSS 0.2%CVE-2026-97634MEDIUMEvent Tickets and Registration <= 5.29.5 - Authenticated (Contributor+) SQL Injection via 'orderby' ParameterEPSS 0.3%CVE-2026-96647MEDIUMListdom: AI-powered Business Directory with Classifieds Ads Listings <= 6.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lsd[remark]' ParameterEPSS 0.2%CVE-2026-95670HIGHNo External Links <= 5.2.0 - Unauthenticated Stored Cross-Site Scripting via Log URL via /goto/{base64} RedirectEPSS 0.2%CVE-2026-93756HIGHSmash Balloon Social Post Feed <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via Facebook Comment Message in Admin Builder PreviewEPSS 0.3%CVE-2026-100107HIGHKubio AI Page Builder <= 2.9.2 - Unauthenticated Stored Cross-Site Scripting via SVG Comment Content (KSES Allowlist Bypass)EPSS 0.3%CVE-2026-96871HIGHMang Board <= 2.4.2 - Unauthenticated Stored Cross-Site Scripting via 'data_type' ParameterEPSS 0.2%CVE-2026-97342HIGHJetFormBuilder <= 3.6.5.4 - Unauthenticated Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post ActionEPSS 0.2%CVE-2026-103426HIGHRelevanssi Premium <= 2.31.4 - Unauthenticated Stored Cross-Site Scripting via '_rt' ParameterEPSS 0.2%CVE-2026-96566HIGHNewsletter <= 9.4.0 - Unauthenticated Stored Cross-Site Scripting via 'np1' Custom Field ParameterEPSS 0.3%CVE-2026-102002LOWOtter Blocks <= 3.2.6 - Authenticated (Subscriber+) Sensitive Information Exposure in Form Submissions Dashboard WidgetEPSS 0.3%CVE-2026-12951MEDIUMMultiVendorX <= 5.0.18 - Authenticated (Store Manager+) SQL Injection via 'order_by' ParameterEPSS 0.3%CVE-2026-100182HIGHDownload Monitor <= 5.2.10 - Unauthenticated Stored Cross-Site Scripting via Cross-Origin postMessage to Admin EditorEPSS 0.3%CVE-2026-97641HIGHRelevanssi <= 4.28.3 - Unauthenticated Stored Cross-Site Scripting via Comment ContentEPSS 0.2%CVE-2026-102772HIGHCMB2 <= 2.13.1 - Unauthenticated Stored Cross-Site Scripting via 'textarea_code' FieldEPSS 0.3%