Busca de CVEs
398.559 resultadosCVE-2026-89032HIGHBerriAI LiteLLM < 1.101.0-rc.1 Tenant Isolation Bypass via Semantic Cache LayerEPSS 0.3%CVE-2026-67234LOWRabbitMQ: Non-RFC-conformant cookie name when clearing the auth-mechanism preferenceEPSS 0.6%CVE-2026-67225MEDIUMRabbitMQ: Stream-protocol frame length never validated against frame_maxEPSS 0.3%CVE-2026-67230MEDIUMRabbitMQ: Web-STOMP unbounded pre-auth accumulationEPSS 0.5%CVE-2026-67222MEDIUMRabbitMQ: list_to_atom on auth_mechanism URI tokens in amqp_clientEPSS 0.3%CVE-2026-97871MEDIUMZhonglun CloudPos JSBridge JSBridge.cs OpenLocalBrowser code injectionEPSS 0.5%CVE-2026-67236HIGHRabbitMQ: Plaintext username:password stored in an insecure cookie after successful POST /loginEPSS 0.1%CVE-2026-92161CRITICALFriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth providerEPSS 0.3%CVE-2026-42322CRITICALPiwigo: Authenticated RCE via File Upload in Logo Upload FeatureEPSS 0.5%CVE-2026-42324HIGHPiwigo: Second-Order SQL InjectionEPSS 0.9%CVE-2026-44642HIGHPiwigo: SQL injection in upgrade authentication allows unauthenticated upgrade authorization bypass (PHP 8+)EPSS 1.3%CVE-2026-62262CRITICALPiwigo: Unauthenticated SQL injection in `pwg.images.filteredSearch.create`EPSS 0.3%CVE-2026-42323HIGHPiwigo: SQL Injection in Batch ManagerEPSS 0.4%CVE-2026-97469MEDIUMPostgreSQL Anonymizer: RESTRICTED functions are reachable through a subLinkEPSS 0.1%CVE-2026-49850HIGHInvoicePlane: Missing CSRF Protection on State-Changing delete ActionsEPSS 0.3%CVE-2026-50547HIGHInvoicePlane permits local file inclusion through the e-invoice XML configuration identifierEPSS 0.5%CVE-2026-33639HIGHInvoicePlane permits DDL injection through tax_rate_decimal_placesEPSS 0.4%CVE-2026-100230MEDIUMInput Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / versEPSS 0.7%CVE-2026-39353CRITICALInvoicePlane: Remote Code Execution via Writable Templates DirectoryEPSS 0.4%CVE-2026-85293MEDIUMInvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mailer FormsEPSS 0.2%