Busca de CVEs

398.478 resultados
CVE-2026-14603HIGHWowOptin < 1.4.38 - Unauthenticated Opt-in Deactivation and Template Row InjectionEPSS 0.4%CVE-2026-12981HIGHCAFEHAUS API <= 1.0.0 - Unauthenticated Arbitrary User Password ResetEPSS 0.6%CVE-2026-12877CRITICALSoftware Issue Manager < 5.1.0 - Unauthenticated SQL Injection via Search ParameterEPSS 0.4%CVE-2026-12690LOWProfileGrid < 5.9.9.7 - Subscriber+ Premium License Tampering via Missing AuthorizationEPSS 0.3%CVE-2026-12689MEDIUMProfileGrid < 5.9.9.7 - Subscriber+ Cross-User Private Message Thread Deletion and Tampering via Missing AuthorizationEPSS 0.2%CVE-2026-12688MEDIUMProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN ForgeryEPSS 0.3%CVE-2026-12497HIGHProfilePress < 4.16.18 - Unauthenticated Privilege Escalation via Registration Role SelectionEPSS 0.4%CVE-2026-14172HIGHRapid7 InsightVM, Nexpose, and Insight Agent Local Privilege Escalation via Unvalidated Executable InvocationEPSS 0.2%CVE-2026-16870HIGHMultiple Security Vulnerabilities in Snowflake libsnowflakeclientEPSS 0.5%CVE-2026-66141HIGHExim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.EPSS 0.1%CVE-2026-66140HIGHExim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because argumentsEPSS 0.4%CVE-2026-66139MEDIUMOpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.EPSS 0.5%CVE-2026-66138HIGHIn OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a runniEPSS 0.8%CVE-2026-54422MEDIUMIn OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extracEPSS 0.1%CVE-2026-11922MEDIUMRate-limit Bypass in zenml-io/zenmlEPSS 0.3%CVE-2026-11354MEDIUMParticipants Database <= 2.7.8.3 - Missing Authorization to Unauthenticated Arbitrary Record Update / Sensitive Information Exposure via 'id' ParameterEPSS 0.4%CVE-2026-12736HIGHWPify Woo <= 5.4.16 - Authenticated (Shop Manager+) Privilege Escalation via Arbitrary Option Update via save_option REST EndpointEPSS 0.6%CVE-2025-9205MEDIUMMapSVG Lite <= 8.14.0 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2026-15420MEDIUMNexter Blocks <= 5.0.0 - Authenticated (Subscriber+) Path Traversal to Arbitrary CSS/JS File Deletion via 'plus_name' ParameterEPSS 0.9%CVE-2026-13464MEDIUMKirki <= 6.0.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'context' ParameterEPSS 0.5%