Busca de CVEs
398.152 resultadosCVE-2026-86066MEDIUMHorilla attendance approval endpoint is vulnerable to cross-site request forgeryEPSS —CVE-2026-96795HIGHHorilla: Authenticated RCE in Horilla List-View ExportEPSS —CVE-2026-57449HIGHActual Sync Server: CORS Proxy GitHub API Allowlist Prefix Bypass Leaks Private Repositories Through the Server GitHub TokenEPSS —CVE-2026-100502MEDIUMFlame through 2.4.0 Admin Token Insufficient Session ExpirationEPSS —CVE-2026-100501HIGHFlame through 2.4.0 Brute-Force Attack via Login EndpointEPSS —CVE-2026-100419HIGHgitoxide gix-fs before 0.23.0 Worktree Escape via SymlinkEPSS —CVE-2026-100418MEDIUMFlame through 2.4.0 Information Exposure via GET /api/configEPSS —CVE-2026-71483HIGHHorilla: Reflected Cross-Site Scripting (XSS) in Employee Filter ViewEPSS —CVE-2026-63432MEDIUMHorilla: Server-Side Template Injection (SSTI) in Mail Preview Endpoints Allows Authenticated Users to Disclose Password Hashes and Server MetadataEPSS —CVE-2026-63431MEDIUMHorilla: Missing Authorization on Payroll Component Views Exposes Employee Salary Structures and Personal Loan Records (IDOR)EPSS —CVE-2026-88003HIGHInvoicePlane: Failure to Revoke Administrative Privileges After Role DowngradeEPSS —CVE-2026-92842MEDIUMOOB read / info leak in convert.* stream filters when line-break-chars contains NULEPSS —CVE-2026-91768MEDIUMIPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcmp 12 bytes)EPSS —CVE-2026-100383MEDIUMStored i18n XSS in WikiLambda's VisualEditor integrationEPSS —CVE-2026-100382CRITICALUnauthenticated remote code execution through wikitext in ExternalDataEPSS —CVE-2026-100381MEDIUMUploadWizard Flickr collection and set titles allow DOM XSSEPSS —CVE-2026-91769MEDIUMTLS Hostname Verification Falls Back to CN After SAN MismatchEPSS —CVE-2026-100380MEDIUMReflected XSS in Wikibase Special:SetLabel language validationEPSS —CVE-2026-100379MEDIUMCross-request disclosure of CentralAuth cookies in Wikipedia Android AppEPSS —CVE-2026-91767MEDIUMHeap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard CNEPSS —