Búsqueda de CVEs
400.818 resultadosCVE-2026-5782MEDIUMReflected XSS in Loglama.NET's TurkHotspotEPSS —CVE-2026-104026HIGHIn Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed EPSS —CVE-2026-104614MEDIUMCodeAstro Simple Pharmacy Management System delete.php sql injectionEPSS —CVE-2026-94422HIGHxdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escapeEPSS —CVE-2026-19652CRITICALDivi Membership <= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id' ParameterEPSS —CVE-2026-93875HIGHJetAppointment <= 2.5.2.1 - Unauthenticated Stored Cross-Site Scripting via 'friendlyTime' ParameterEPSS —CVE-2026-104721MEDIUMLogback: Incomplete protection against CVE-2026-19880EPSS —CVE-2026-104613MEDIUMCodeAstro Simple Pharmacy Management System view.php sql injectionEPSS —CVE-2026-85215HIGHSQL Injection in GG Soft's PaperworkEPSS —CVE-2026-66054MEDIUMApache Thrift: C++ THeaderTransport does not enforce configured maxFrameSizeEPSS —CVE-2026-61374HIGHApache Thrift: Java TSaslTransport post-auth data-frame missing size limitEPSS —CVE-2026-63772HIGHApache Thrift: Unauthenticated single-packet crash of Go Thrift servers via the THeader transform countEPSS —CVE-2026-66055HIGHApache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TJSONProtocol accepts a single JSON string/number exceeding the configured size limit (multi-language)EPSS —CVE-2026-104612MEDIUMSourceCodester Student Result Management System Announcement new_announcement.php cross site scriptingEPSS —CVE-2026-11795MEDIUMUser Enumeration in Softtr's E-Commerce PackEPSS —CVE-2026-102797MEDIUMWordPress ThemeREX Addons plugin <= 2.46.0 - Server Side Request Forgery (SSRF) vulnerabilityEPSS —CVE-2026-102798MEDIUMWordPress ThemeREX Addons plugin <= 2.46.0 - Cross Site Scripting (XSS) vulnerabilityEPSS —CVE-2026-66081HIGHApache Thrift: c_glib read_message_begin leaves output parameters unset for non-versioned messagesEPSS —CVE-2026-66331MEDIUMApache Thrift: Buffered transport reads are not accounted against MaxMessageSizeEPSS —CVE-2026-66837HIGHApache Thrift: PHP accelerator sizes a stack buffer from a wire-controlled string lengthEPSS —