Busca de CVEs

390.652 resultados
CVE-2026-52476HIGHSQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the getPageData method in the DEPSS 0.5%CVE-2026-30632HIGHDirectory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.EPSS 0.7%CVE-2026-16327MEDIUMD-Link DNS-320 upload.php unrestricted uploadEPSS 1.6%CVE-2026-63728HIGHGitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template FeatureEPSS 0.2%CVE-2026-55833HIGHNetty SPDY zlib header block continues decoded expansion after maxHeaderSize truncationEPSS 0.4%CVE-2026-55831HIGHNetty SPDY SETTINGS frame count materializes unbounded settings mapEPSS 0.4%CVE-2026-15905HIGHUse after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a maliciEPSS 0.2%CVE-2026-15904HIGHUse after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specifEPSS 0.3%CVE-2026-15903HIGHOut of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sanEPSS 0.6%CVE-2026-15902HIGHUse after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a cEPSS 0.3%CVE-2026-15901CRITICALUse after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crEPSS 0.4%CVE-2026-15900CRITICALUse after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape EPSS 0.4%CVE-2026-15899CRITICALUse after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox eEPSS 0.4%CVE-2026-57495HIGHAgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)EPSS 0.4%CVE-2026-57852MEDIUMAuthentication Bypass via Null Short-Circuit in Grav CMS Scheduler Webhook Token CheckEPSS 0.7%CVE-2026-57494HIGHAgenticMail: Cross-agent task authorization bypass in AgenticMail APIEPSS 0.4%CVE-2026-47255HIGHAgenticMail API/storage and outbound relay hardeningEPSS 0.3%CVE-2026-64626MEDIUMAVideo Encoder downloadURL SSRF via unpinned retry fallbackEPSS 0.3%CVE-2026-64625CRITICALAVideo before 29.0 OS Command Injection via execAsyncEPSS 0.6%CVE-2026-64624HIGHFreeRDP RDP File Parser Remote Code Execution via CLI OptionsEPSS 0.2%