Búsqueda de CVEs
399.514 resultadosCVE-2026-102278HIGHbrace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustionEPSS 0.4%CVE-2026-97027LOWFlatpak: flatpak: denial of service via unsanitized keys in exported desktop entry / d-bus service filesEPSS 0.1%CVE-2026-97026LOWFlatpak: flatpak: world-writable temporary child repositories in system-helper cache pathEPSS 0.1%CVE-2026-97025LOWFlatpak: flatpak: world-readable oci authentication token in system-helper cache pathEPSS 0.1%CVE-2026-102277MEDIUMbrace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of serviceEPSS 0.3%CVE-2026-102276HIGHbrace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustionEPSS 0.4%CVE-2026-102265MEDIUMPyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token headerEPSS 0.3%CVE-2026-102006MEDIUMVxWorks 7 Memory allocationEPSS 0.1%CVE-2026-102275MEDIUMPyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusionEPSS 0.1%CVE-2026-101187CRITICALZiroom ZHOME A0101 USB Device Management API zrUsb.lua pop_usb_device command injectionEPSS 2.3%CVE-2026-91096—In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destroy in releases beforEPSS 0.1%CVE-2026-91095—In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStEPSS 0.1%CVE-2026-84895—In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSeEPSS 0.1%CVE-2026-102274MEDIUMPyJWT: Malformed RSA JWK aborts parsing of an entire JWK SetEPSS 0.4%CVE-2026-102273HIGHPyJWT accepts public JWK containers as HMAC secretsEPSS 0.2%CVE-2026-102272HIGHPyJWT BOM BypassEPSS 0.2%CVE-2026-102271HIGHPyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guardEPSS 0.2%CVE-2026-101146MEDIUMEleveo Quality Management GWT RPC QMUtilsService UtilsService.createAndSaveAudit information disclosureEPSS 0.3%CVE-2026-102270MEDIUMPyJWT: ReDoS vulnerability when calling the `is_pem_format` function.EPSS 0.2%CVE-2026-102269MEDIUMPyJWT: Non-canonical signature segments enable raw-token revocation bypassEPSS 0.2%