Busca de CVEs
390.660 resultadosCVE-2026-63102MEDIUMrConfig Core < 8.2.8 Privilege Escalation via Users API role fieldEPSS 0.3%CVE-2026-28220HIGHWazuh cluster DAPI arbitrary callable deserialization and RBAC context injection allow a cluster peer to execute privileged functions on the master nodeEPSS 0.4%CVE-2026-6793MEDIUMStored XSS in Bifra Engineering's Q-smart NexT PollEPSS 0.2%CVE-2026-27823HIGHRemote Code Execution Vulnerability in EGroupwareEPSS 1.0%CVE-2026-46415HIGHCaddy Defender trusted proxy client IP bypassEPSS 0.2%CVE-2026-21824HIGHA privilege escalation vulnerability affects HCL CommerceEPSS 0.4%CVE-2026-48824MEDIUMMailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)EPSS 0.4%CVE-2026-45713HIGHMailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizesEPSS 0.4%CVE-2026-45712MEDIUMMailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)EPSS 0.2%CVE-2026-26199MEDIUMBuffer underflow in `H5Iget_name `/`H5G_get_name` if size is zeroEPSS 0.3%CVE-2026-26197MEDIUMArray full size, element count, and element size are not checked to make sure they match in H5Odtype.cEPSS 0.3%CVE-2026-25039HIGHThe application evaluate UNC path in workspace nameEPSS 0.5%CVE-2026-45711MEDIUMMailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDsEPSS 0.3%CVE-2026-45709MEDIUMMailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialerEPSS 0.3%CVE-2026-13724MEDIUMBusiness Logic Bypass in Gobito's Corporate Training Management SystemEPSS 0.3%CVE-2026-46412CRITICALMalicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud wormEPSS 0.8%CVE-2026-62418HIGHApache Syncope: Low-privileged authenticated SSRF in Connectors and Resources checkEPSS 0.5%CVE-2026-46516MEDIUMFrogman vulnerable to stored XSS in chat console formatter (escalation vector in multi-admin deployments)EPSS 0.4%CVE-2026-62183CRITICALApache Syncope: User self-service privilege escalationEPSS 0.7%CVE-2026-63091HIGHProFTPD mod_sftp Signed Integer Overflow via SCP Size-Record ParserEPSS 0.5%