Busca de CVEs

398.504 resultados
CVE-2026-65898MEDIUMDOMPurify before 3.4.11 Permanent Attribute Allowlist Pollution via setConfigEPSS 0.3%CVE-2026-14257HIGHbrace-expansion DoS via unbounded expansion length causing an out-of-memory process crashEPSS 0.6%CVE-2026-15037LOWXML injection vulnerability in QDom comment, CDATA and processing-instruction serializationEPSS 0.4%CVE-2026-65907CRITICALIn JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possibleEPSS 0.7%CVE-2026-65908HIGHIn JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project openEPSS 0.2%CVE-2026-65906HIGHIn JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possibleEPSS 0.7%CVE-2026-65475MEDIUMWordPress Modula Image Gallery plugin 2.14.25-2.14.30 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-61945MEDIUMWordPress WooCommerce Product Stock Alert plugin <= 3.0.6 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2026-57626HIGHWordPress MailPoet plugin 5.30.0-5.33.0 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.1%CVE-2026-65897HIGHGrav API Plugin 1.0.9 Privilege Escalation via Invitations groupsEPSS 0.5%CVE-2026-65896HIGHGrav API Plugin before 1.0.10 Path Traversal via moveEPSS 0.5%CVE-2026-65895HIGHGrav API Plugin before 1.0.10 Broken Access ControlEPSS 0.3%CVE-2026-65608HIGHGrav before 2.0.9 Remote Code Execution via FlexDirectoryEPSS 1.3%CVE-2026-65607HIGHSiYuan before v3.7.2 Path Traversal via /export/temp/EPSS 0.6%CVE-2026-65606CRITICALSiYuan before v3.7.2 Cross-Site Scripting to RCEEPSS 0.8%CVE-2026-65605CRITICALSiYuan before v3.7.2 Stored XSS to RCE via Attribute ViewEPSS 0.8%CVE-2026-64815HIGHIn JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form filesEPSS 0.5%CVE-2026-64814HIGHIn JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development sessionEPSS 0.4%CVE-2026-64813CRITICALIn JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development sessionEPSS 0.5%CVE-2026-64812CRITICALIn JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development sessionEPSS 0.5%