Busca de CVEs

398.697 resultados
CVE-2026-6084MEDIUMStored Cross-Site Scripting in StockAgile by Novadigits technologiesEPSS 0.2%CVE-2026-6083MEDIUMStored Cross-Site Scripting in StockAgile by Novadigits technologiesEPSS 0.2%CVE-2026-6082MEDIUMStored Cross-Site Scripting in StockAgile by Novadigits technologiesEPSS 0.2%CVE-2026-92550HIGHApache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoderEPSS 0.4%CVE-2026-92560HIGHApache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoderEPSS 0.4%CVE-2026-92573MEDIUMApache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON renderingEPSS 0.3%CVE-2026-97863MEDIUMmisp-modules: Shell Command Injection in MISP cisco_firesight_manager_ACL_rule_export Module via Unescaped Attribute ValuesEPSS 0.3%CVE-2026-92564—Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processingEPSS 0.2%CVE-2026-92608HIGHApache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10EPSS 0.3%CVE-2026-92609CRITICALApache Qpid Broker-J: Missing HTTP-session renewal after successful authenticationEPSS 0.4%CVE-2026-95864HIGHThemify Builder <= 7.8.1 - Unauthenticated Stored Cross-Site Scripting via 'css[fonts]' ParameterEPSS 0.3%CVE-2026-89426HIGHKnit Pay <= 9.6.1.0 - Authenticated (Subscriber+) Privilege Escalation via Gravity Forms Role FieldEPSS 0.5%CVE-2026-94573HIGHRepeater Fields for Elementor Forms <= 2.2.7 - Unauthenticated Stored Cross-Site Scripting via Repeater Field ValueEPSS 0.2%CVE-2026-19804HIGHs2Member <= 260814 - Unauthenticated Remote Code Execution via 'first_name' Parameter in PayPal Proxy ReturnEPSS 1.0%CVE-2026-84280HIGHFancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via Shortcode Order 'elements[].title' ParameterEPSS 0.3%CVE-2026-12037MEDIUMAsset CleanUp: Page Speed Booster <= 1.4.0.5 - Authenticated (Administrator+) Server-Side Request Forgery via 'page_url' ParameterEPSS 0.3%CVE-2026-89406HIGHModula Image Gallery <= 3.0.1 - Missing Authorization to Unauthenticated Private Gallery Image Disclosure via 'modula_gallery_id' and 'modula_image_id' ParametersEPSS 0.4%CVE-2026-93901HIGHOptima Express IDX <= 8.7.5 - Unauthenticated Privilege Escalation to 'ihf_clear_cache' AJAX Action to Author Role AssignmentEPSS 0.3%CVE-2026-13179MEDIUMWP Maps <= 4.9.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via shapes_values ParameterEPSS 0.3%CVE-2026-17602MEDIUMSSL Zen <= 4.7.42 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'file_name' ParameterEPSS 0.6%