Busca de CVEs

398.539 resultados
CVE-2026-100303MEDIUMTDuck survey form through 6.0 Missing Authorization in Form Theme Management EndpointsEPSS 0.3%CVE-2026-97897MEDIUMKrayin laravel-crm TinyMCE Media Upload Sanitizer.php cross site scriptingEPSS 0.2%CVE-2026-53629HIGHGLPI: SQL injection in history tabEPSS 1.0%CVE-2026-53626HIGHGLPI: Arbitrary Document Read via Form Context Authorization BypassEPSS 0.3%CVE-2026-48482CRITICALGLPI: RCE via Form importEPSS 0.3%CVE-2026-53625HIGHGLPI: Privilege Escalation via authtype API manipulationEPSS 0.6%CVE-2026-53610HIGHGLPI: Reflected XSS in dashboardsEPSS 0.4%CVE-2026-47679HIGHGLPI: arbitrary file deletionEPSS 0.3%CVE-2026-55214HIGHGLPI: Stored XSS in suppliersEPSS 0.3%CVE-2026-49470HIGHGLPI: Missing Rate Limiting on Login and TOTP Verification — Account Takeover via Brute ForceEPSS 0.4%CVE-2026-97896MEDIUMkrayin laravel-crm Upload Functionality ConfigurationForm.php rules cross site scriptingEPSS 0.2%CVE-2026-55217MEDIUMGLPI: Unallowed modfication of knowbase items comments and translationsEPSS 0.3%CVE-2026-53628MEDIUMGLPI: Unallowed authentication method update by administratorEPSS 0.5%CVE-2026-45801MEDIUMGLPI: Unauthorized Debug Mode Activation via Profile Update (Privilege Escalation)EPSS 0.3%CVE-2026-53627MEDIUMGLPI: Unexpected access to update operations through the APIEPSS 0.3%CVE-2026-49469MEDIUMGLPI: LDAP filter injection in user import featureEPSS 0.4%CVE-2026-63208MEDIUMZammad: Microsoft Graph error logs expose partially masked OAuth access tokensEPSS 0.3%CVE-2026-63006MEDIUMZammad: HTML sanitizer API path allowlist bypass via interior path traversal in img src/srcsetEPSS 0.5%CVE-2026-63204LOWZammad: Authenticated agents can read AI summary error messages from inaccessible ticketsEPSS 0.3%CVE-2026-61855MEDIUMZammad: Invalid PGP Detached Signatures Reported as Good Signature on Inbound MailEPSS 0.2%