Busca de CVEs
390.665 resultadosCVE-2026-46412CRITICALMalicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud wormEPSS 0.8%CVE-2026-62418HIGHApache Syncope: Low-privileged authenticated SSRF in Connectors and Resources checkEPSS 0.5%CVE-2026-46516MEDIUMFrogman vulnerable to stored XSS in chat console formatter (escalation vector in multi-admin deployments)EPSS 0.4%CVE-2026-62183CRITICALApache Syncope: User self-service privilege escalationEPSS 0.7%CVE-2026-63091HIGHProFTPD mod_sftp Signed Integer Overflow via SCP Size-Record ParserEPSS 0.5%CVE-2026-63090HIGHProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet ReassemblyEPSS 0.9%CVE-2026-57308CRITICALApache Syncope: SQL injection vulnerability in Audit Events searchEPSS 0.8%CVE-2026-53421CRITICALApache Syncope: Remote Code Execution via Scripted ConnectorEPSS 0.7%CVE-2026-54910HIGHFileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary filesEPSS 0.5%CVE-2026-53405CRITICALApache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTaskEPSS 0.7%CVE-2026-63071CRITICALApache Syncope: RCE via Groovy Sandbox bypassEPSS 0.8%CVE-2026-12701CRITICALPulpcore: pulpcore: relative_path_validator bypass via directory traversal in filesystemexportEPSS 1.2%CVE-2026-54685MEDIUMFileBrowser Quantum has Username Enumeration via Authentication Timing Side-ChannelEPSS 0.5%CVE-2026-46410HIGHFileBrowser Quantum: unauthenticated user share share infoEPSS 0.4%CVE-2026-45270HIGHCI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation RuleEPSS 0.4%CVE-2026-16277MEDIUMRpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()EPSS 0.5%CVE-2026-16252MEDIUMBeijing Shenzhou Shihan Technology Multimedia Integrated Business Display System Staffshinel Ds.jsp sql injectionEPSS 0.4%CVE-2026-45139MEDIUMCI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operationsEPSS 0.5%CVE-2026-59238MEDIUMStored XSS in Pentestify via unsanitized finding images and report client logoEPSS 0.6%CVE-2026-57311MEDIUMUnrestricted Upload of File with Dangerous Type in Windu CMSEPSS 0.6%