Busca de CVEs

395.442 resultados
CVE-2026-16763MEDIUMlocalstack serverless-localstack Configuration index.js os command injectionEPSS 1.2%CVE-2026-6924HIGHWeak entropy initialization in Silicon Labs Matter SiWx917 TinyCrypt pathEPSS 0.4%CVE-2026-16002HIGHOut-of-bounds Read in MZ Automation lib60870EPSS 0.4%CVE-2026-50032HIGHNULL Pointer Dereference in MZ Automation libIEC61850EPSS 0.5%CVE-2026-50103HIGHImproper Handling of Syntactically Invalid Structure in MZ Automation libIEC61850EPSS 0.3%CVE-2026-49035CRITICALStack-based Buffer Overflow in MZ Automation libIEC61850EPSS 0.6%CVE-2026-15981CRITICALSAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse ParameterEPSS 0.8%CVE-2026-50039HIGHStack-based Buffer Overflow in MZ Automation libIEC61850EPSS 0.5%CVE-2026-34496HIGHvictor Web - Priviledge EscalationEPSS 0.3%CVE-2026-47724CRITICALnebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalationEPSS 0.5%CVE-2026-21653HIGHCCure and Victor Application Server - Server Side Request ForgeryEPSS 0.4%CVE-2026-47723HIGHnebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)EPSS 0.5%CVE-2026-21655HIGHC-CURE 9000 and Victor application server - Deserialization of Untrusted DataEPSS 0.5%CVE-2026-16796HIGHImproper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()EPSS 0.6%CVE-2026-15968HIGHStored XSS vulnerability in MOVEit TransferEPSS 0.2%CVE-2026-15967HIGHMOVEit Transfer refresh-token processing does not enforce updated account restrictionsEPSS 0.2%CVE-2026-15966HIGHImproper CORS handling in MOVEit TransferEPSS 0.2%CVE-2026-15630CRITICALCVE-2026-15630EPSS 0.3%CVE-2026-10697HIGHMFA Bypass in MOVEit TransferEPSS 0.3%CVE-2026-15212HIGHWPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 43.2 - Cross-Site Request Forgery to Privilege Escalation via Plugin Settings UpdateEPSS 0.2%