Busca de CVEs

390.659 resultados
CVE-2026-54051CRITICALNetwork-AI has an an OS Command Injection issueEPSS 0.7%CVE-2026-35590MEDIUMPossible out-of-bounds read leading to crash when decoding well-crafted EXIF metadataEPSS 0.1%CVE-2026-33328MEDIUMPossible integer overflow on 32-bit systems when reading GIF imagesEPSS 0.1%CVE-2026-33327HIGHPossible integer overflow leading to potential heap-based buffer overflowEPSS 0.2%CVE-2026-32825HIGHdataCycle No Brute-Force Protection On Web And API Login EndpointsEPSS 0.3%CVE-2026-32824HIGHdataCycle User API Password Reset And Confirmation Flows Trust Attacker- Controlled Redirect TargetsEPSS 0.3%CVE-2026-32823MEDIUMdataCycle State-Changing GET Endpoints Enable CSRFEPSS 0.1%CVE-2026-32821HIGHAPI Collection Impersonation Via user_email And Missing Object- Level AuthorizationEPSS 0.4%CVE-2026-32806HIGHdataCycle Authorization Bypass Via /remote_renderEPSS 0.4%CVE-2026-32820HIGHdataCycle Public Markdown Path Traversal Via /docs/*pathEPSS 0.9%CVE-2026-32819MEDIUMdataCycle User Directory Enumeration Via /users/searchEPSS 0.3%CVE-2026-46671MEDIUMRust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directoryEPSS 0.2%CVE-2026-63429HIGHHeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form contextEPSS 0.5%CVE-2026-63428MEDIUMHeyForm: completeSubmission persists submitter-supplied hidden fields verbatim without validating against the form's declared hidden-field setEPSS 0.3%CVE-2026-35198CRITICALHeyForm vulnerable to stored XSS via form field titlesEPSS 0.5%CVE-2026-45797MEDIUMHeyForm Vulnerable to Stored XSS via Unauthenticated SVG File UploadEPSS 0.6%CVE-2026-46428CRITICALlettre has TLS hostname verification disabled when using Boring TLS backendEPSS 0.3%CVE-2026-32822MEDIUMdataCycle Unauthenticated Reflected DOM XSS Via flash[...] On Public PagesEPSS 0.3%CVE-2026-32807HIGHdataCycle Public DataLink Text File Download Ignores Validity And AuthorizationEPSS 0.4%CVE-2026-63102MEDIUMrConfig Core < 8.2.8 Privilege Escalation via Users API role fieldEPSS 0.3%