Búsqueda de CVEs
400.908 resultadosCVE-2026-76147MEDIUMGenians, Inc Genian NAC/ZTNA Remote Code ExecutionEPSS —CVE-2026-76146HIGHGenians, Inc Genian SSL PNS OS Command InjectionEPSS —CVE-2026-76145HIGHGenians, Inc Genian SSL PNS Improper Privilege ManagementEPSS —CVE-2026-76144LOWGenians, Inc Genian SSL PNS Unrestricted File UploadEPSS —CVE-2026-76143HIGHGenians, Inc Genian SSL PNS Multi Factor Authentication BypassEPSS —CVE-2026-76142CRITICALGenians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal InterfaceEPSS —CVE-2026-78210HIGHIn affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an environment without EPSS —CVE-2026-103538MEDIUMZongXR SuperMarket Order Deletion Endpoint OrderController.java OrderController.deleteOrder missing authenticationEPSS —CVE-2026-92966CRITICALAppointment Booking Plugin <= 5.7.0 - Unauthenticated Arbitrary Shortcode Execution via First/Last Name FieldEPSS —CVE-2026-12241MEDIUMAdvanced Woo Labels – Product Labels & Badges for WooCommerce <= 2.51 - Improper Authorization to Authenticated (Subscriber+) Stored Cross-Site ScriptingEPSS —CVE-2026-92548MEDIUMWP Popular Posts <= 7.4.2 - Unauthenticated Information Disclosure in 'post_type' and 'context' ParametersEPSS —CVE-2026-103536MEDIUMZongXR Supermarket save Endpoint OrderController.java OrderController.addOrder missing authenticationEPSS —CVE-2026-103641MEDIUMGegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoderEPSS —CVE-2026-103534MEDIUMDavid-Crty databasement Snapshot Model snapshots SnapshotPolicy.view access controlEPSS —CVE-2026-91109MEDIUMSimply Schedule Appointments <= 1.6.12.31 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'complete_group' ParameterEPSS —CVE-2026-96561HIGHAI Engine <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'model_' Parameter → PHP Error-Log Injection → Advisor Indirect Prompt InjectionEPSS —CVE-2026-92245HIGHSimply Schedule Appointments <= 1.6.12.32 - Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via 'recursive' Parameter on the appointment_types REST Endpoint via Public NonceEPSS —CVE-2026-103533LOWDavid-Crty databasement database-servers API Endpoint RestoreRequest.php 511 path traversalEPSS —CVE-2026-101887LOWBlueALSA bluealsad LC3plus Decoder Division-by-Zero DoSEPSS —CVE-2026-92537MEDIUMNewsletter <= 9.3.9 - Unauthenticated Insufficiently Protected Credentials via '/tnp/l/' Click-Tracking REST Endpoint (Raw Subscriber Token Cookie Disclosure)EPSS —