Busca de CVEs

395.560 resultados
CVE-2026-61390HIGHThere is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunctiEPSS 0.4%CVE-2026-57600HIGHInsufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sEPSS 0.4%CVE-2026-57599MEDIUMThere is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attacEPSS 0.4%CVE-2026-16473MEDIUMSbc: sbc: heap out-of-bounds read via crafted sbc audio frameEPSS 0.2%CVE-2026-14551HIGHLocal Privilege Escalation in servereye client (sensorhub)EPSS 0.1%CVE-2026-2406MEDIUMIDOR in Universe Software's Online Registration and Workflow Management SystemEPSS 0.4%CVE-2026-15787MEDIUMUltimate Addons for Elementor <= 2.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon AttributesEPSS 0.4%CVE-2026-63264MEDIUMJoomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3EPSS 0.4%CVE-2026-63048CRITICALJoomla Extension - joomlack.fr - Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2EPSS 0.4%CVE-2026-63047HIGHJoomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1EPSS 0.4%CVE-2026-45820MEDIUMfflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory EPSS 0.3%CVE-2026-3821HIGHSupermicro SMASH service contain an Arbitrary code execution issueEPSS 0.6%CVE-2026-14322MEDIUMTimetics < 1.0.57 - Unauthenticated Booking Auto-Approval via Arbitrary payment_methodEPSS 0.3%CVE-2026-12987HIGHEvents Manager < 7.3.7 - Unauthenticated SQL Injection via PHP Object Injection in Booking RegistrationEPSS 0.5%CVE-2026-12968HIGHProduct Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG UploadEPSS 0.5%CVE-2026-15802HIGHWP Foodbakery <= 4.9 - Authenticated (Subscriber+) Arbitrary File Deletion via via delete_locations_backup_file AJAX ActionEPSS 0.8%CVE-2026-16492MEDIUMumijs umi GIT File Helper getFileGitIno.ts git.getFileCreateInfo os command injectionEPSS 3.9%CVE-2026-56844HIGHA vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges andEPSS 0.2%CVE-2026-16490MEDIUMitsourcecode Hospital Management System prescription.php sql injectionEPSS 0.3%CVE-2025-44089HIGHAn issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.EPSS 0.3%