Busca de CVEs
395.450 resultadosCVE-2026-47752CRITICALTugtainer has Server-Side Template Injection in notification templates that leads to Remote Code ExecutionEPSS 0.5%CVE-2026-65763MEDIUMJoomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4EPSS 0.4%CVE-2026-65759HIGHJoomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1EPSS 0.4%CVE-2026-16768MEDIUMGdk-pixbuf: out-of-bounds read in ico parserEPSS 0.2%CVE-2026-65761CRITICALJoomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1EPSS 0.9%CVE-2026-65760CRITICALJoomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1EPSS 0.4%CVE-2026-65698MEDIUMVoid 1.3.4 Path Traversal via AI Agent File-Reading ToolsEPSS 0.5%CVE-2026-65697MEDIUMFathom Lite 1.3.1 Stored XSS via /collect EndpointEPSS 0.3%CVE-2026-44909HIGHProxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could expEPSS 0.6%CVE-2026-65696MEDIUMOverseerr 1.35.0 Authorization Bypass via pushSubscriptions APIEPSS 0.3%CVE-2026-65695HIGHOffice-Word-MCP-Server 1.1.11 Path Traversal via document toolsEPSS 0.5%CVE-2026-65917HIGHCyberPanel IncBackups IDOR via Sequential Backup IDEPSS 0.5%CVE-2026-65916HIGHCyberPanel Missing Authorization in cancelBackupCreation HandlerEPSS 0.5%CVE-2026-15611CRITICALUnverified email-based SSO account linkingEPSS 0.4%CVE-2026-15612CRITICALLOIDC nonce validation bypassEPSS 0.2%CVE-2026-15614HIGHIdP-initiated SAML sessions not reliably invalidated (replay)EPSS 0.2%CVE-2026-15615HIGHSAML <Conditions> element not validatedEPSS 0.2%CVE-2026-15616CRITICALLocal MFA not enforced during SSO sign-inEPSS 0.3%CVE-2026-15617CRITICALPrincipal/domain lookup without case normalizationEPSS 0.4%CVE-2026-16584HIGHAWS API MCP Server Security Policy Bypass via Startup FailureEPSS 0.2%