Busca de CVEs

398.702 resultados
CVE-2026-96039HIGHBA Book Everything <= 1.8.27 - Unauthenticated Stored Cross-Site Scripting via first_name ParameterEPSS 0.2%CVE-2026-93303HIGHHT Contact Form <= 2.10.1 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'form_data' Rich Text Field via Draft Save/ResumeEPSS 0.2%CVE-2026-93399CRITICALOnline Scheduling and Appointment Booking System <= 28.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' ParameterEPSS 0.4%CVE-2026-92799MEDIUMOnline Scheduling and Appointment Booking System <= 28.2 - Unauthenticated Authorization Bypass via PHP Type Juggling via 'verification_code' Parameter Type Juggling via json_dataEPSS 0.3%CVE-2026-92829MEDIUMBlog2Social: Social Media Auto Post & Scheduler <= 9.1.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via Multiple AJAX HandlersEPSS 0.3%CVE-2026-96766MEDIUMGeoDirectory <= 2.8.183 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'business_hours' ParameterEPSS 0.2%CVE-2026-89055CRITICALCustomer Reviews for WooCommerce <= 5.120.0 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'items[][media]' ParameterEPSS 0.4%CVE-2026-19775MEDIUMOpenStation <= 1.1.7 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via AI Copilot Search EndpointEPSS 0.2%CVE-2026-84279HIGHFancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via 'output_format' Parameter via Pro Export Print JobEPSS 0.2%CVE-2026-93899MEDIUMBetter Messages <= 3.0.4 - Authenticated (Subscriber+) SQL Injection via 'group_id' Message Meta ParameterEPSS 0.3%CVE-2026-84281HIGHFancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via 'productTitle' in '_fpd_data' Order Item MetaEPSS 0.2%CVE-2026-83591HIGHAMP for WP <= 1.1.16 - Unauthenticated Stored Cross-Site Scripting via Comment Content Regex TransformationEPSS 0.2%CVE-2026-92212MEDIUMJetFormBuilder <= 3.6.5.3 - Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated FieldEPSS 0.2%CVE-2026-93897MEDIUMGeoDirectory <= 2.8.181 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Text-type Custom Field (e.g., 'phone')EPSS 0.2%CVE-2026-62062HIGHWordPress Elementor Website Builder plugin <= 4.3.1 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.1%CVE-2026-75553LOWSmartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an attacker to retrieve a EPSS 0.1%CVE-2026-97846MEDIUMKeycloak-services: keycloak-services: standard token exchange v2 bypasses mtls holder-of-key bindingEPSS 0.1%CVE-2026-78397MEDIUMLink Library < 7.9.6 - Unauthenticated SSRF via Reciprocal Link ValidationEPSS 0.2%CVE-2026-78394MEDIUMLink Library < 7.9.6 - Contributor+ Path Traversal via 'filepath' ParameterEPSS 0.2%CVE-2026-78393MEDIUMLink Library < 7.9.6 - Reflected XSS via 'link_tags' and 'link_price' Sort and Breadcrumb LinksEPSS 0.1%