Busca de CVEs

401.251 resultados
CVE-2026-85291MEDIUMInvoicePlane IDOR: Horizontal Privilege Escalation via Password Change Without Authorization CheckEPSS 0.3%CVE-2026-85289MEDIUMInvoicePlane: Missing CSRF Token Validation on Multiple Delete EndpointsEPSS 0.2%CVE-2026-85292MEDIUMInvoicePlane: Loose Type Comparison in Core Authentication Check (Defense-in-Depth)EPSS 0.3%CVE-2026-85274MEDIUMInvoicePlane: Recurring Invoice State Change via GET Request Without CSRF ProtectionEPSS 0.2%CVE-2026-85290MEDIUMInvoicePlane: Log Injection via Unsanitized User Input in Cron Key Error LoggingEPSS 0.2%CVE-2026-39372MEDIUMInvoicePlane: Sensitive Information Disclosure via Unstripped EXIF Metadata in AttachmentsEPSS 0.3%CVE-2026-54790MEDIUMInvoicePlane: Second-order SQL injection through the unvalidated custom_field_table field in the Custom Fields moduleEPSS 0.2%CVE-2026-97869LOWlangchain4j LangChain4j-agentic AgenticScopeJsonSerializationIT.java AgenticScopeSerializer.fromJson deserializationEPSS 0.4%CVE-2026-97868MEDIUMsheshbabu zen Note Editor NotesEditor.jsx dangerouslySetInnerHTML cross site scriptingEPSS 0.2%CVE-2026-96874LOWStored XSS in Cargo Drilldown tab namesEPSS 0.2%CVE-2026-96812HIGHHost Root Sandbox Escape in gVisor via Character Device Passthrough and CUSEEPSS 0.1%CVE-2026-97866MEDIUMZhonglun CloudPOS Automatic Update Program.cs channel accessibleEPSS 0.3%CVE-2026-93030MEDIUMFTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw.EPSS 0.3%CVE-2026-93306HIGHThis Power System update is being released to addressEPSS 0.2%CVE-2026-84862HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.4%CVE-2026-84882HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.3%CVE-2026-84884HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.2%CVE-2026-84893HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.2%CVE-2026-93647CRITICALZimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Crafted Calendar COUNTER Message From AddressEPSS 0.2%CVE-2026-93643CRITICALZimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas RequestEPSS 1.0%