Busca de CVEs

386.204 resultados
CVE-2026-15718MEDIUMInvalid pointer in the JavaScript: WebAssembly componentEPSS 0.5%CVE-2026-15691HIGHTenda BE12 Pro SafeClientFilter fromSafeClientFilter stack-based overflowEPSS 0.9%CVE-2026-62390CRITICALApache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh APIEPSS 0.7%CVE-2026-15690LOWopen62541 Shared Client ua_client_connect.c responseReadNamespacesArray null pointer dereferenceEPSS 0.4%CVE-2026-9341MEDIUMAcademy LMS <= 3.8.0 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'user_id' ParameterEPSS 0.4%CVE-2026-62422CRITICALIn JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass vEPSS 0.3%CVE-2026-15389HIGHInadequate access control in Sesame Time session managementEPSS 0.4%CVE-2026-3014MEDIUMRemote Code Execution by administrative user on the Management ServerEPSS 0.8%CVE-2026-15043CRITICALDBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on textEPSS 0.4%CVE-2026-58319CRITICALApache Doris: Improper Authentication in Frontend HTTP APIEPSS 0.7%CVE-2026-14852MEDIUMmk_sap_hana: Privilege escalation via crafted sapstartsrv process nameEPSS 0.2%CVE-2026-12478MEDIUMLibsoup: incomplete fix for cve-2026-0716: out-of-bounds read in libsoup websocket frame processing (unmasked path)EPSS 0.4%CVE-2026-56451CRITICALA vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm speciEPSS 0.5%CVE-2026-54429MEDIUMA vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handle high-volume multicEPSS 0.3%CVE-2025-40945HIGHA vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (AlEPSS 0.2%CVE-2024-7708HIGHFor requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case forEPSS 0.4%CVE-2026-15416HIGHArgo-cd: argo cd unauthenticated remote code execution in repo-server via generatemanifest grpc endpointEPSS 0.4%CVE-2026-8384MEDIUMIn Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admiEPSS 0.3%CVE-2026-6790MEDIUMIn Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what pEPSS 0.3%CVE-2026-10051MEDIUMIn Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the EPSS 0.4%