Búsqueda de CVEs

398.691 resultados
CVE-2026-82379HIGHApache Roller: WSSE digest authentication headers can be replayedEPSS —CVE-2026-82380HIGHApache Roller: CSRF protection bypass via self-generated salt validationEPSS —CVE-2026-82381MEDIUMApache Roller: Stored cross-site scripting in the authoring UIEPSS —CVE-2026-82382MEDIUMApache Roller: Reflected cross-site scripting in the frontpage directory parameterEPSS —CVE-2026-82383HIGHApache Roller: Anonymous setup action allows frontpage configuration tamperingEPSS —CVE-2026-82384CRITICALApache Roller: Unauthenticated deserialization in the XML-RPC endpointEPSS —CVE-2026-82375HIGHApache Roller: Server-side request forgery via entry trackback and enclosure URLsEPSS —CVE-2026-82376HIGHApache Roller: XML external entity processing in trackback response parserEPSS —CVE-2026-82377CRITICALApache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlersEPSS —CVE-2026-82378CRITICALApache Roller: OAuth authorization endpoint trusts request-supplied identityEPSS —CVE-2026-101012MEDIUMmathurvishal CloudClassroom-PHP-Project makeresult.php sql injectionEPSS —CVE-2026-82385MEDIUMApache Roller: Weblog template include escapes the Velocity sandbox and reads classpath filesEPSS —CVE-2026-82386HIGHApache Roller: XML external entity processing in OPML bookmark importEPSS —CVE-2026-82348HIGHApache Roller: Cross-weblog resource tampering via unscoped authoring lookupsEPSS —CVE-2026-82387MEDIUMApache Roller: Stored cross-site scripting via uploaded media content typeEPSS —CVE-2026-82546MEDIUMApache Roller: Stored cross-site scripting through incoming Trackback linksEPSS —CVE-2026-91204MEDIUMApache Roller: Stored javascript: URI in HTML commentsEPSS —CVE-2026-91206MEDIUMApache Roller: Reflected XSS in the optional LDAP comment authenticatorEPSS —CVE-2026-101011MEDIUMaaPanel BaoTa Domain domainMod.py get_domain_status sql injectionEPSS —CVE-2026-101010MEDIUMaaPanel BaoTa data.py getData sql injectionEPSS —