Busca de CVEs
389.872 resultadosCVE-2026-3183HIGHMulti Factor Auth BypassEPSS 1.2%CVE-2026-8082HIGHBpost Shipping Platform < 3.2.3 - Unauthenticated SQL InjectionEPSS 0.4%CVE-2026-14185MEDIUMWPBot AI ChatBot < 8.2.0 - Subscriber+ RAG Settings UpdateEPSS 0.3%CVE-2026-14184MEDIUMAcademy LMS < 3.8.1 - Subscriber+ Cross-User Lesson Note and Progress Modification via IDOREPSS 0.2%CVE-2026-14183MEDIUMClassified Listing < 5.3.9 - Subscriber+ Payment Receipt Disclosure via IDOREPSS 0.3%CVE-2026-13694MEDIUMBit Form < 3.1.0 - Unauthenticated Workflow Trigger via Authentication BypassEPSS 0.3%CVE-2026-13693MEDIUMBit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path TraversalEPSS 0.4%CVE-2026-11767HIGHCRT Addons for Elementor < 1.6.7 - Unauthenticated Stored XSS via Contact FormEPSS 0.5%CVE-2026-13439CRITICALEasy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Administrator via Password Recovery REST EndpointEPSS 0.4%CVE-2026-15782MEDIUMWPForms <= 2.0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post ContentEPSS 0.3%CVE-2026-3182MEDIUMSensitive Data ExposureEPSS 0.6%CVE-2026-15811MEDIUMKronosnet: kronosnet: encryption key exposure in memory after cryptographic configuration changesEPSS 0.1%CVE-2026-15812MEDIUMKronosnet: kronosnet: access control list bypass via link id spoofing on unencrypted dynamic linksEPSS 0.3%CVE-2023-37507MEDIUMAn information disclosure vulnerability affects HCL DevOps PlanEPSS 0.2%CVE-2026-16266MEDIUMVersions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attackerEPSS 0.4%CVE-2026-15927MEDIUMQuay: mirror-registry: ssrf: repo-level mirror accepts external_reference without url validationEPSS 0.5%CVE-2023-37508LOWHCL DevOps Plan is susceptible to a Cross-Site Scripting (XSS) vulnerabilityEPSS 0.1%CVE-2026-15156MEDIUMEssential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color SettingsEPSS 0.3%CVE-2026-59776HIGHMissing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is explEPSS 0.1%CVE-2026-16336MEDIUMtrinodb trino OAuth2/OIDC ExternalUriInfo.java redirectEPSS 0.4%