Busca de CVEs

401.399 resultados
CVE-2026-42323HIGHPiwigo: SQL Injection in Batch ManagerEPSS 0.4%CVE-2026-97469MEDIUMPostgreSQL Anonymizer: RESTRICTED functions are reachable through a subLinkEPSS 0.1%CVE-2026-49850HIGHInvoicePlane: Missing CSRF Protection on State-Changing delete ActionsEPSS 0.3%CVE-2026-50547HIGHInvoicePlane permits local file inclusion through the e-invoice XML configuration identifierEPSS 0.5%CVE-2026-33639HIGHInvoicePlane permits DDL injection through tax_rate_decimal_placesEPSS 0.4%CVE-2026-100230MEDIUMInput Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / versEPSS 0.7%CVE-2026-39353CRITICALInvoicePlane: Remote Code Execution via Writable Templates DirectoryEPSS 0.4%CVE-2026-85293MEDIUMInvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mailer FormsEPSS 0.2%CVE-2026-85291MEDIUMInvoicePlane IDOR: Horizontal Privilege Escalation via Password Change Without Authorization CheckEPSS 0.3%CVE-2026-85289MEDIUMInvoicePlane: Missing CSRF Token Validation on Multiple Delete EndpointsEPSS 0.2%CVE-2026-85292MEDIUMInvoicePlane: Loose Type Comparison in Core Authentication Check (Defense-in-Depth)EPSS 0.3%CVE-2026-85274MEDIUMInvoicePlane: Recurring Invoice State Change via GET Request Without CSRF ProtectionEPSS 0.2%CVE-2026-85290MEDIUMInvoicePlane: Log Injection via Unsanitized User Input in Cron Key Error LoggingEPSS 0.2%CVE-2026-39372MEDIUMInvoicePlane: Sensitive Information Disclosure via Unstripped EXIF Metadata in AttachmentsEPSS 0.3%CVE-2026-54790MEDIUMInvoicePlane: Second-order SQL injection through the unvalidated custom_field_table field in the Custom Fields moduleEPSS 0.2%CVE-2026-97869LOWlangchain4j LangChain4j-agentic AgenticScopeJsonSerializationIT.java AgenticScopeSerializer.fromJson deserializationEPSS 0.4%CVE-2026-97868MEDIUMsheshbabu zen Note Editor NotesEditor.jsx dangerouslySetInnerHTML cross site scriptingEPSS 0.2%CVE-2026-96874LOWStored XSS in Cargo Drilldown tab namesEPSS 0.2%CVE-2026-96812HIGHHost Root Sandbox Escape in gVisor via Character Device Passthrough and CUSEEPSS 0.1%CVE-2026-97866MEDIUMZhonglun CloudPOS Automatic Update Program.cs channel accessibleEPSS 0.3%