Busca de CVEs
396.964 resultadosCVE-2025-44090HIGHAn issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.EPSS 0.3%CVE-2026-16489MEDIUMjsforce SFDX Connection Registry sfdx.js _execCommand os command injectionEPSS 1.1%CVE-2026-16488LOWQUSETIONS MiniCode-Python Project File config.py subprocess.Popen os command injectionEPSS 1.5%CVE-2026-63263MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceEPSS 0.2%CVE-2026-63262MEDIUMMissing Authorization in Kibana Leading to Information DisclosureEPSS 0.3%CVE-2026-63261MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2026-63260MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2026-16486MEDIUMSourceCodester Class and Exam Timetabling System BSIS.php cross site scriptingEPSS 0.5%CVE-2026-16517LOWLibarchive: libarchive: signed integer overflow in archive_write_zip_headerEPSS 0.1%CVE-2026-63259MEDIUMAuthorization Bypass Through User-Controlled Key in Kibana Leading to Information DisclosureEPSS 0.3%CVE-2026-63145MEDIUMIncorrect Authorization in Kibana Leading to Machine Learning Audit Log Integrity CompromiseEPSS 0.3%CVE-2026-63144MEDIUMUncontrolled Recursion in Elasticsearch Leading to Denial of ServiceEPSS 0.2%CVE-2026-56820HIGHNetty: Missing CertificateID Validation in OCSP Response Allows Replay AttacksEPSS 0.2%CVE-2026-56819HIGHNetty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)EPSS 0.4%CVE-2026-63143MEDIUMMissing Authorization in Kibana Leading to Unauthorized Information DisclosureEPSS 0.3%CVE-2026-56817HIGHNetty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enabledEPSS 0.4%CVE-2026-63142MEDIUMIncomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request ForgeryEPSS 0.3%CVE-2026-16424CRITICALUse after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer processEPSS 0.3%CVE-2026-16423HIGHUse after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gesturEPSS 0.3%CVE-2026-16422HIGHInsufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileEPSS 0.2%