Busca de CVEs
389.947 resultadosCVE-2026-13381HIGHVSee Clinic and API Insecure Direct Object Reference in File API Allows Unauthorized File Access and DeletionEPSS 0.2%CVE-2026-53594MEDIUMFreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted PathEPSS 0.5%CVE-2026-13380CRITICALVSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP ResponsesEPSS 0.2%CVE-2026-44585MEDIUMPaymenter: Broken object level authorization via service reference manipulation on ticket creationEPSS 0.3%CVE-2026-44583MEDIUMPaymenter: Blind Unauthenticated SSRF on the Paypal gateway moduleEPSS 0.4%CVE-2026-44584MEDIUMPaymenter doesn't reset email verification status after email changeEPSS 0.2%CVE-2026-53593HIGHFreeScout Vulnerable to Authenticated Remote Code Execution via incomplete upload extension denylist (.pht) — bypass of CVE-2025-48471EPSS 0.5%CVE-2026-53592MEDIUMFreeScout vulnerable to prototype pollution in getQueryParamEPSS 0.2%CVE-2026-53591HIGHFreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMAC Length Bypass in FetchEmailsEPSS 0.4%CVE-2026-44230MEDIUMRT: Reflected Cross-Site Scripting in search results chartEPSS 0.3%CVE-2026-44231CRITICALRT: Privilege escalation and information disclosure via REST 2.0 user collection endpointEPSS 0.4%CVE-2026-44229MEDIUMRT: Cross-Site Scripting via inline-served uploaded contentEPSS 0.2%CVE-2026-63766CRITICALGPT-SoVITS 20250606v2pro OS Command Injection via webui.pyEPSS 1.7%CVE-2026-16337CRITICALImproper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms EPSS 0.5%CVE-2026-63767CRITICALktransformers Unauthenticated Pickle Deserialization RCE via ZMQEPSS 1.1%CVE-2026-15788MEDIUMWCOW cache mount source selector resolves NTFS junctions outside of cache rootEPSS 0.3%CVE-2026-63768MEDIUMcal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned StateEPSS 0.3%CVE-2026-63769MEDIUMHuginn 2022.08.18 SSRF via ScenarioImport fetch_url MethodEPSS 0.4%CVE-2026-63770HIGHGlance 0.8.5 IP Spoofing Authentication Brute-Force Protection BypassEPSS 0.3%CVE-2026-63771MEDIUMAdminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix HeaderEPSS 0.4%