Busca de CVEs

390.537 resultados
CVE-2026-47708CRITICALMCP-for-Stata: Command injection via log_file_name parameter in Stata command wrapperEPSS 0.5%CVE-2026-47697HIGHShelf has cross-organization IDOR: authenticated users could read/attach another workspace's assets, tags, custodians, bookings, QR codes and audit dataEPSS 0.3%CVE-2026-47695HIGHCC-Tweaked has an SSRF Protection Bypass with NAT64EPSS 0.5%CVE-2026-63092MEDIUMkirby-modules License Key Disclosure via modules/activate DialogEPSS 0.3%CVE-2026-47237HIGHKubeflow Community Distribution: Overly Permissive Istio Permissions Allows Kubeflow Authorization Token StealingEPSS 0.4%CVE-2026-65056HIGHmcp-webresearch Server-Side Request Forgery in visit_page Due to Missing Internal-IP FilteringEPSS 0.4%CVE-2026-47690HIGHMeltanoHub vulnerable to command injection in the `test_dispatcher` GitHub Actions workflowEPSS 0.5%CVE-2026-65055MEDIUMTaiga taiga-back Private Project Member Roster Disclosure via Unauthenticated filters_data EndpointsEPSS 0.4%CVE-2026-44879HIGHAuthenticated Command Injection allows arbitrary command execution in CLI InterfaceEPSS 1.7%CVE-2026-47689MEDIUMFOGProject has stored XSS via unescaped inventory data in buildRow() rendered on Group Inventory tabEPSS 0.3%CVE-2026-44878HIGHAuthenticated Path Traversal allows Unauthorized Access in Web InterfaceEPSS 0.6%CVE-2026-47688HIGHFOGProject has unauthenticated clearAES and clearPMTasks that allow remote destruction of host encryption keys and power schedulesEPSS 0.2%CVE-2026-47687HIGHFOGProject has stored XSS via unescaped option label in selectForm() accessible from unauthenticated inventory endpointEPSS 0.3%CVE-2026-47685HIGHFOGProject has stored XSS via unauthenticated inventory service renders unescaped in Host Management pageEPSS 0.2%CVE-2026-63764HIGHLMDeploy Server-Side Request Forgery via HTTP Redirect BypassEPSS 0.4%CVE-2026-63139MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2026-46556MEDIUMFlaskBB: SSRF in get_image_info() via unrestricted avatar URLEPSS 0.4%CVE-2026-64821MEDIUMdjangoSIGE 1.10 CSRF via GET-based Order Cancellation ViewsEPSS 0.2%CVE-2026-65054HIGHMediaCMS Private Media Metadata Disclosure via Playlist Ownership LoopholeEPSS 0.3%CVE-2026-64822MEDIUMdjangoSIGE 1.10 User Enumeration via ForgotPasswordViewEPSS 0.4%