Busca de CVEs
389.902 resultadosCVE-2025-68640MEDIUMThe Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate dEPSS 0.4%CVE-2026-50757HIGHDirectory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draEPSS 0.6%CVE-2026-52476HIGHSQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the getPageData method in the DEPSS 0.5%CVE-2026-30633HIGHDirectory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools.EPSS 0.9%CVE-2026-30632HIGHDirectory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.EPSS 0.7%CVE-2025-66390CRITICALIn Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in TenantEPSS 0.6%CVE-2026-50758HIGHCross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp paraEPSS 0.7%CVE-2026-52472CRITICALSQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml fileEPSS 0.6%CVE-2026-52469CRITICALSQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml fileEPSS 0.6%CVE-2026-50755CRITICALAn issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header valueEPSS 0.6%CVE-2026-52470CRITICALSQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml fileEPSS 0.6%CVE-2026-50759HIGHAn issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instance/{instance_id} endEPSS 0.7%CVE-2026-50756HIGHAn issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider componentEPSS 0.5%CVE-2026-16327MEDIUMD-Link DNS-320 upload.php unrestricted uploadEPSS 1.6%CVE-2026-63728HIGHGitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template FeatureEPSS 0.2%CVE-2026-55833HIGHNetty SPDY zlib header block continues decoded expansion after maxHeaderSize truncationEPSS 0.4%CVE-2026-55831HIGHNetty SPDY SETTINGS frame count materializes unbounded settings mapEPSS 0.4%CVE-2026-15905HIGHUse after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a maliciEPSS 0.2%CVE-2026-15904HIGHUse after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specifEPSS 0.3%CVE-2026-15903HIGHOut of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sanEPSS 0.6%