Busca de CVEs
399.998 resultadosCVE-2026-9729MEDIUMWeb Push Notifications <= 4.39.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'webpushr_notification_title' Post Meta ParameterEPSS 0.3%CVE-2026-12421HIGHARforms <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'password' Field ValuesEPSS 0.3%CVE-2026-59678HIGHportprotonqt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManagerEPSS 0.2%CVE-2026-59677MEDIUMProcess Kill Attack Vector in killall() in seunshareEPSS 0.1%CVE-2026-59676MEDIUMLocal File Deletion Attack Vector in rm_rf() in seunshareEPSS 0.1%CVE-2026-9577MEDIUMPost Status Notifier Lite < 1.13.0 - Reflected XSS via mod ParameterEPSS 0.2%CVE-2026-9066MEDIUMWP Compress < 7.10.04 - Reflected XSS via test_zoneEPSS 0.3%CVE-2026-14291HIGHSecurity Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2faEPSS 0.5%CVE-2026-12082HIGHPraison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure)EPSS 0.4%CVE-2026-64600HIGHxfs: resample the data fork mapping after cycling ILOCKEPSS 0.2%CVE-2026-7232HIGHFormCraft <= 3.9.14 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Sub-ParametersEPSS 0.3%CVE-2026-7534HIGHSUMO Reward Points for WooCommerce <= 32.7.0 - Unauthenticated Stored Cross-Site Scripting via 'reason' ParameterEPSS 0.3%CVE-2026-63226MEDIUMPrinters and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing toEPSS 0.4%CVE-2026-6390MEDIUMNano: gnu nano: arbitrary memory writes, information disclosure, or denial of service via format string vulnerability in error handling.EPSS 0.2%CVE-2026-15074HIGH@fastify/static vulnerable to route guard bypass via path traversalEPSS 0.7%CVE-2026-7120MEDIUM@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL PathsEPSS 0.4%CVE-2026-21723MEDIUMCVE-2026-21723 RecordEPSS 0.3%CVE-2026-16653MEDIUMboazsegev facil.io Public Folder http.c http_sendfile2 path traversalEPSS 0.7%CVE-2026-38764HIGHAn issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sysEPSS 0.1%CVE-2026-39155MEDIUMKnot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name can be computed incoEPSS 0.2%