Busca de CVEs

388.455 resultados
CVE-2026-35148MEDIUMHCL DFXServer is affected by a Missing Access Control vulnerabilityEPSS 0.3%CVE-2026-35146MEDIUMHCL DFXServer is affected by an Unencrypted Communication vulnerability.EPSS 0.2%CVE-2023-49899CRITICALOrigin Validation Error in X-Rite MA-T6EPSS 0.3%CVE-2023-49900CRITICALOrigin Validation Error in X-Rite MA-T6EPSS 1.0%CVE-2026-22752CRITICALSpring Security Authorization Server Dynamic Client Registration endpoints perform insufficient validation of client metadataEPSS 0.5%CVE-2026-6424MEDIUMUse-after-free vulnerability in ESET security products for LinuxEPSS 0.2%CVE-2026-15324MEDIUMSysBasics Customize My Account for WooCommerce <= 4.4.14 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'row_type' ParameterEPSS 0.3%CVE-2026-15103HIGHWPFunnels <= 3.12.8 - Authenticated (Funnel Manager+) Privilege Escalation via 'group_id' Path ParameterEPSS 0.3%CVE-2026-15727MEDIUMWP Bulk Delete <= 1.4.2 - Authenticated (Administrator+) SQL Injection via 'delete_user_roles' ParameterEPSS 0.6%CVE-2026-15021MEDIUMwpForo Forum <= 3.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'location' Profile FieldEPSS 0.4%CVE-2026-15005HIGHLoco Translate <= 2.8.5 - Cross-Site Request Forgery to Remote Code Execution via 'template' ParameterEPSS 0.3%CVE-2026-13741HIGHDigits: WordPress Mobile Number Signup and Login <= 9.1.0.5 - Authenticated (Subscriber+) Privilege Escalation via 'digits_reg_userrole' ParameterEPSS 0.4%CVE-2026-58078HIGHJoomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1EPSS 0.4%CVE-2026-6423HIGHLocal privilege escalation via unauthenticated ALPC in ESET Inspect ConnectorEPSS 0.2%CVE-2026-13755MEDIUMTickera <= 3.6.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'price_wrapper' Shortcode AttributeEPSS 0.4%CVE-2026-15610MEDIUMWPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() FunctionEPSS 0.4%CVE-2026-15106MEDIUMWPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' ParameterEPSS 0.5%CVE-2026-15407MEDIUMThemify Builder <= 7.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Stylesheet Write/Delete via tb_generate_on_fly AJAX ActionEPSS 0.5%CVE-2026-15651MEDIUMWP TripAdvisor Review Slider <= 14.6 - Authenticated (Administrator+) SQL Injection via 'filtersource' ParameterEPSS 0.5%CVE-2026-15008HIGHUncanny Automator <= 7.3.1.4 - Unauthenticated PHP Object Injection to Arbitrary File Deletion via Forminator Submitted-Field TokenEPSS 1.0%