Busca de CVEs

398.400 resultados
CVE-2026-48036HIGHHulumi: Drift classifier fails open on adapter errors and over-promotes Mixed verdictsEPSS 0.5%CVE-2026-48035HIGHHulumi: AccountFoundation audit-delivery S3 bucket could be silently weakenedEPSS 0.5%CVE-2026-48033HIGHHulumi: Policy packs bypassed by a forged Pulumi-URN logical nameEPSS 0.5%CVE-2026-48032HIGHHulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providersEPSS 0.5%CVE-2026-48034HIGHHULUMI-H5 bypass via decoy sibling resources targeting a different bucketEPSS 0.4%CVE-2026-48021CRITICALepa4all Security Incident: Implement keystore based on Telematik TSL, implement hostname check and certificate check for lib-vauEPSS 0.2%CVE-2026-54342HIGHTLS Certificate Verification Disabled on CXF Transport Clients in epa4allEPSS 0.2%CVE-2026-66035HIGHlibssh2 Heap Buffer Overflow via ETM Cipher NegotiationEPSS 0.6%CVE-2026-66034HIGHlibssh2 Heap Out-of-Bounds Read via publickey subsystemEPSS 0.4%CVE-2026-66033HIGHlibssh2 Integer Underflow DoS via AES-GCM Cipher NegotiationEPSS 0.7%CVE-2026-66032HIGHlibssh2 Double-Free Heap Corruption via sftp_open()EPSS 0.4%CVE-2026-65623HIGHQuadratic CPU blow-up reassembling fragmented WebSocket messages in BanditEPSS 0.6%CVE-2026-65711HIGHsysPass 3.2.11 Authenticated OS Command Injection via Backup PathEPSS 2.0%CVE-2026-65710HIGHsysPass 3.2.11 Missing Authorization via PublicLinkController Account DecryptionEPSS 0.3%CVE-2026-65709HIGHsysPass 3.2.11 Missing Object-Level Authorization via JSON-RPC APIEPSS 0.4%CVE-2026-65708HIGHsysPass 3.2.11 Insecure Direct Object Reference via AccountFileControllerEPSS 0.4%CVE-2026-65707HIGHLikeshop 3.0.5 Authenticated SQL Injection via adjustAccount EndpointEPSS 0.5%CVE-2026-65693HIGHMicroweber CMS 2.0.20 Server-Side Template Injection via Mail TemplatesEPSS 0.9%CVE-2026-64255HIGHwifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlersEPSS 0.2%CVE-2026-64254—NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAREPSS 0.1%