Busca de CVEs
398.467 resultadosCVE-2026-15464MEDIUMWP Hotel Booking <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'widget_search' Shortcode AttributeEPSS 0.3%CVE-2026-15653MEDIUMVisualizer <= 4.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'backend-title' ParameterEPSS 0.3%CVE-2026-12654MEDIUMPayment Plugins for Stripe WooCommerce <= 4.0.7 - Missing Authorization to Unauthenticated Arbitrary Order Status Modification via Empty Webhook SecretEPSS 0.6%CVE-2026-15648MEDIUMBrands for WooCommerce <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'width' Shortcode AttributeEPSS 0.3%CVE-2026-15334MEDIUMCozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon.view' Block AttributeEPSS 0.4%CVE-2026-15755MEDIUMOpen User Map <= 1.4.45 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode AttributesEPSS 0.4%CVE-2026-15333MEDIUMCozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'cozyCustomFont' Block AttributeEPSS 0.4%CVE-2026-15665MEDIUMFluent Support <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'redirect-to' Shortcode AttributeEPSS 0.3%CVE-2026-16910MEDIUMQuay: ssrf in red hat quay notification webhooks (slack/generic)EPSS 0.3%CVE-2026-14603HIGHWowOptin < 1.4.38 - Unauthenticated Opt-in Deactivation and Template Row InjectionEPSS 0.4%CVE-2026-12981HIGHCAFEHAUS API <= 1.0.0 - Unauthenticated Arbitrary User Password ResetEPSS 0.6%CVE-2026-12877CRITICALSoftware Issue Manager < 5.1.0 - Unauthenticated SQL Injection via Search ParameterEPSS 0.4%CVE-2026-12690LOWProfileGrid < 5.9.9.7 - Subscriber+ Premium License Tampering via Missing AuthorizationEPSS 0.3%CVE-2026-12689MEDIUMProfileGrid < 5.9.9.7 - Subscriber+ Cross-User Private Message Thread Deletion and Tampering via Missing AuthorizationEPSS 0.2%CVE-2026-12688MEDIUMProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN ForgeryEPSS 0.3%CVE-2026-12497HIGHProfilePress < 4.16.18 - Unauthenticated Privilege Escalation via Registration Role SelectionEPSS 0.4%CVE-2026-14172HIGHRapid7 InsightVM, Nexpose, and Insight Agent Local Privilege Escalation via Unvalidated Executable InvocationEPSS 0.2%CVE-2026-16870HIGHMultiple Security Vulnerabilities in Snowflake libsnowflakeclientEPSS 0.5%CVE-2026-66141HIGHExim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.EPSS 0.1%CVE-2026-66140HIGHExim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because argumentsEPSS 0.4%