Busca de CVEs

397.448 resultados
CVE-2026-65430HIGHJoomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extensionEPSS 0.2%CVE-2026-65431CRITICALJoomla Extension - regularlabs.com - Zipslip in GeoIP extensionEPSS 0.4%CVE-2026-15011CRITICALCustomer Support Ticket System & Helpdesk <= 6.0.5 - Unauthenticated Code Injection via 'path' ParameterEPSS 0.5%CVE-2026-14282CRITICALGoDAM <= 1.12.2 - Unauthenticated Arbitrary File Upload via WPForms File Upload FieldEPSS 0.7%CVE-2026-15794MEDIUMGrid/List View for WooCommerce <= 3.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'position' Shortcode AttributeEPSS 0.3%CVE-2026-14481MEDIUMEqualize Digital Accessibility Checker <= 1.46.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'html' ParameterEPSS 0.4%CVE-2026-15906MEDIUMPremium Packages <= 7.0.4 - Authenticated (Admin+) SQL Injection via 'orderby' ParameterEPSS 0.5%CVE-2026-15646MEDIUMBrands for WooCommerce <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode AttributeEPSS 0.3%CVE-2026-15647MEDIUMBrands for WooCommerce <= 3.8.8 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta FieldEPSS 0.3%CVE-2026-15761MEDIUMTickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_event_filter' ParameterEPSS 0.5%CVE-2026-15827MEDIUMGutenKit <= 2.4.12 - Missing Authorization to Unauthenticated Sensitive Information Exposure via Mailchimp REST EndpointsEPSS 0.5%CVE-2026-15404MEDIUMBulk Page Generator <= 2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post TitleEPSS 0.3%CVE-2026-16078MEDIUMWCPOS <= 1.9.8 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read via 'type' ParameterEPSS 0.6%CVE-2026-16723CRITICALRemote Code Execution in fastjson 1.2.68–1.2.83EPSS 16.0%CVE-2026-52688HIGHRRSIGs with too few labels can lead to bypass of DNSSEC wildcard validationEPSS 0.1%CVE-2026-52686LOWWildcard CNAME proof validation bypassEPSS 0.1%CVE-2024-58330HIGHA missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analyticEPSS 0.5%CVE-2024-58023HIGHInformation disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.EPSS 0.1%CVE-2026-52684LOWPrefetch Feature Allows Persistent Ghost Domain Cache Poisoning AttackEPSS 0.1%CVE-2026-16287HIGHRoot Command Injection via Offline Update in TÜBİTAK BİLGEM's pardus-updateEPSS 0.8%