Busca de CVEs

390.676 resultados
CVE-2026-26081MEDIUMHAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also EPSS 0.5%CVE-2026-26483MEDIUMMettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. TheEPSS 0.3%CVE-2026-26080LOWHAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALEPSS 0.5%CVE-2024-51313CRITICALThe Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg.EPSS 0.6%CVE-2024-51316HIGHThe Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /goform/SetOnlineDevNaEPSS 0.5%CVE-2024-51314CRITICALThe Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg.EPSS 0.6%CVE-2026-51031HIGHFlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. This allows a remote EPSS 0.5%CVE-2024-51312CRITICALThe Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg.EPSS 0.6%CVE-2024-51311CRITICALThe Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList.EPSS 0.6%CVE-2026-51027CRITICALAn issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.EPSS 0.6%CVE-2026-52656CRITICALAn issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute aEPSS 0.7%CVE-2026-51385MEDIUMAn issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url,EPSS 0.5%CVE-2026-51025MEDIUMCross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary code via the ClientEPSS 0.4%CVE-2026-52349HIGHDirectory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute aEPSS 0.4%CVE-2026-51026MEDIUMDirectory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a crafted request.EPSS 1.3%CVE-2024-51315CRITICALThe Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevNameEPSS 0.6%CVE-2026-45138MEDIUMCI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation RuleEPSS 0.2%CVE-2026-42566HIGHMeshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failureEPSS 0.5%CVE-2026-44359CRITICALMeshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI WorkflowEPSS 1.8%CVE-2026-12484HIGHUnsafe Deserialization in keras.layers.TorchModuleWrapper.from_configEPSS 0.4%