Busca de CVEs

386.208 resultados
CVE-2026-15595MEDIUMSourceCodester Class and Exam Timetabling System forsubject.php cross site scriptingEPSS 0.5%CVE-2026-58410HIGHChurchCRM: Improper object-level authorization allows low-privileged users to read and modify other families’ recordsEPSS 0.3%CVE-2026-15594MEDIUMwaooAI waoowaoo Media hash.ts stablePublicIdFromStorageKey improper authorizationEPSS 0.5%CVE-2026-58409CRITICALChurchCRM: Authenticated Remote Code Execution (RCE) via Malicious Plugin UploadEPSS 0.8%CVE-2026-48363HIGHColdFusion | Uncontrolled Search Path Element (CWE-427)EPSS 0.3%CVE-2026-48364HIGHColdFusion | Uncontrolled Search Path Element (CWE-427)EPSS 0.3%CVE-2026-58408MEDIUMChurchCRM : Broken Access Control in `CSVCreateFile.php` Allows Low-Privileged Users to Export All Members' PIIEPSS 0.4%CVE-2026-12385MEDIUMSmart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via 'keyword' ParameterEPSS 0.4%CVE-2026-12536MEDIUMAvada Builder <= 3.15.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Module TitleEPSS 0.3%CVE-2026-55771HIGHCedarJava has policy injection, type confusion, and incorrect equality comparison vulnerabilitiesEPSS 0.6%CVE-2026-55773HIGHCedarJava has a policy injection vulnerabilityEPSS 0.5%CVE-2026-55772HIGHCedarJava has a type confusion vulnerabilityEPSS 0.5%CVE-2026-14906MEDIUMMalicious webpage titles could allow overwriting of bundled PDF resources when saving webpages as PDFs in Firefox for iOSEPSS 0.3%CVE-2026-6875CRITICALSandbox Escape in ServiceNow AI PlatformEPSS 77.6%CVE-2026-49972HIGHLaravel-Mediable < 7.0.0 File Upload RCE via Extension BypassEPSS 1.1%CVE-2026-49971MEDIUMLaravel-Mediable < 7.0.0 Stored XSS via SVG File UploadEPSS 0.4%CVE-2026-49970HIGHLaravel-Mediable < 7.0.0 Path Traversal via File::sanitizePath()EPSS 1.0%CVE-2026-49969MEDIUMLaravel-Mediable < 7.0.0 SSRF via RemoteUrlAdapter URL HandlingEPSS 0.4%CVE-2026-58228MEDIUMScheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link>EPSS 0.6%CVE-2026-60103MEDIUMBlender 3.0.0 - 5.1.2 Out-of-Bounds Read via crafted .blend SDNA blockEPSS 0.2%