Busca de CVEs

390.013 resultados
CVE-2026-39878CRITICALChamilo stored XSS via user registration leads to admin account takeoverEPSS 0.4%CVE-2026-46555HIGHWhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltrationEPSS 0.2%CVE-2026-55238MEDIUMxrdp: Malformed Confirm Active capability sets cause out-of-bounds readsEPSS 0.3%CVE-2026-42210MEDIUMWebmin 2FA requirement bypassEPSS 0.5%CVE-2026-58484HIGHNetwork-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruningEPSS 0.2%CVE-2026-40187HIGHAuthenticated RCE via Malicious eTemplate Upload in EGroupwareEPSS 0.9%CVE-2026-54538HIGHxrdp: Pre-auth infinite loop via totalLength=0 in TS_SHARECONTROLHEADEREPSS 0.4%CVE-2026-39879HIGHSQL injection in syslog-ng SQL destionation driverEPSS 0.3%CVE-2026-44978MEDIUMxrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-of-bounds read in HMAC verificationEPSS 0.3%CVE-2026-39385HIGHFrappe LMS enrollment bypass in paid courses via unrelated batchEPSS 0.4%CVE-2026-44178HIGHxrdp: Channel Data Forwarding Fixed-Size Buffer OverflowEPSS 0.5%CVE-2026-50743MEDIUMA CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones cEPSS 0.1%CVE-2026-55645MEDIUMxrdp: Out-of-bounds read in Client Control PDU processing (xrdp_rdp_process_data_control)EPSS 0.3%CVE-2026-47276MEDIUMNULL Pointer Dereference in REST API properties_parse via Malformed user_propertiesEPSS 0.4%CVE-2026-42218MEDIUMXRDP is vulnerable to a server timing attack, leading to user enumerationEPSS 0.3%CVE-2026-47275LOWnanomq NULL Pointer Dereference in MQTTv5 Client CONNECT Decoder Leading to Remote DoSEPSS 0.3%CVE-2026-41521HIGHxrdp: lib_framebuffer_update Has Integer Overflow Heap Info Leak & ASLR BypassEPSS 0.4%CVE-2026-35217MEDIUMNanoMQ Incorrectly Accepts a Malformed SUBSCRIBE and Can Be Driven into an ASAN-Detectable Out-of-Bounds ReadEPSS 0.3%CVE-2026-58482MEDIUMNetwork-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actionsEPSS 0.2%CVE-2026-46701HIGHNetwork-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default SecretEPSS 0.2%