Busca de CVEs
390.652 resultadosCVE-2026-55219MEDIUMPaymenter: Race condition in payWithCredit() enables credit double-spendEPSS 0.2%CVE-2026-47198HIGHPaymenter: URL parameter injection bypasses paid plan limits at checkoutEPSS 0.4%CVE-2026-53596MEDIUMFreeScout has unrestricted file upload without rate limiting that leads to resource exhaustion (DoS)EPSS 0.4%CVE-2026-53595CRITICALFreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQLEPSS 1.9%CVE-2026-13381HIGHVSee Clinic and API Insecure Direct Object Reference in File API Allows Unauthorized File Access and DeletionEPSS 0.2%CVE-2026-53594MEDIUMFreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted PathEPSS 0.5%CVE-2026-13380CRITICALVSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP ResponsesEPSS 0.2%CVE-2026-44585MEDIUMPaymenter: Broken object level authorization via service reference manipulation on ticket creationEPSS 0.3%CVE-2026-44583MEDIUMPaymenter: Blind Unauthenticated SSRF on the Paypal gateway moduleEPSS 0.4%CVE-2026-44584MEDIUMPaymenter doesn't reset email verification status after email changeEPSS 0.2%CVE-2026-53593HIGHFreeScout Vulnerable to Authenticated Remote Code Execution via incomplete upload extension denylist (.pht) — bypass of CVE-2025-48471EPSS 0.5%CVE-2026-53592MEDIUMFreeScout vulnerable to prototype pollution in getQueryParamEPSS 0.2%CVE-2026-53591HIGHFreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMAC Length Bypass in FetchEmailsEPSS 0.4%CVE-2026-44230MEDIUMRT: Reflected Cross-Site Scripting in search results chartEPSS 0.3%CVE-2026-44231CRITICALRT: Privilege escalation and information disclosure via REST 2.0 user collection endpointEPSS 0.4%CVE-2026-44229MEDIUMRT: Cross-Site Scripting via inline-served uploaded contentEPSS 0.2%CVE-2026-63766CRITICALGPT-SoVITS 20250606v2pro OS Command Injection via webui.pyEPSS 1.7%CVE-2026-16337CRITICALImproper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms EPSS 0.5%CVE-2026-63767CRITICALktransformers Unauthenticated Pickle Deserialization RCE via ZMQEPSS 1.1%CVE-2026-15788MEDIUMWCOW cache mount source selector resolves NTFS junctions outside of cache rootEPSS 0.3%