Busca de CVEs
399.581 resultadosCVE-2026-15787MEDIUMUltimate Addons for Elementor <= 2.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon AttributesEPSS 0.4%CVE-2026-63264MEDIUMJoomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3EPSS 0.4%CVE-2026-63048CRITICALJoomla Extension - joomlack.fr - Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2EPSS 0.4%CVE-2026-63047HIGHJoomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1EPSS 0.4%CVE-2026-45820MEDIUMfflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory EPSS 0.5%CVE-2026-3821HIGHSupermicro SMASH service contain an Arbitrary code execution issueEPSS 0.6%CVE-2026-14322MEDIUMTimetics < 1.0.57 - Unauthenticated Booking Auto-Approval via Arbitrary payment_methodEPSS 0.3%CVE-2026-12987HIGHEvents Manager < 7.3.7 - Unauthenticated SQL Injection via PHP Object Injection in Booking RegistrationEPSS 0.5%CVE-2026-12968HIGHProduct Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG UploadEPSS 0.5%CVE-2026-15802HIGHWP Foodbakery <= 4.9 - Authenticated (Subscriber+) Arbitrary File Deletion via via delete_locations_backup_file AJAX ActionEPSS 0.8%CVE-2026-16492MEDIUMumijs umi GIT File Helper getFileGitIno.ts git.getFileCreateInfo os command injectionEPSS 3.9%CVE-2026-56844HIGHA vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges andEPSS 0.2%CVE-2026-16490MEDIUMitsourcecode Hospital Management System prescription.php sql injectionEPSS 0.3%CVE-2025-50330HIGHAn issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via EPSS 0.7%CVE-2025-44089HIGHAn issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.EPSS 0.5%CVE-2025-60835HIGHAn issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.EPSS 0.2%CVE-2025-50325MEDIUMBandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-WEPSS 0.5%CVE-2025-50324HIGHAn issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.EPSS 0.7%CVE-2025-50327HIGHAn issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypEPSS 0.7%CVE-2026-38766HIGHAn issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 functionEPSS 0.1%