Busca de CVEs

398.702 resultados
CVE-2026-97721MEDIUMSanluan PublicCMS exportExcel/exportData SysUserAdminController.java CmsContentAdminController authorizationEPSS 0.2%CVE-2026-97818HIGHphpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.EPSS 0.3%CVE-2026-97764LOWdjango-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attackerEPSS 0.2%CVE-2026-97737HIGHIn Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeoveEPSS 0.3%CVE-2026-97736MEDIUMtinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular expression.EPSS 0.2%CVE-2026-97735HIGHITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive overEPSS 0.3%CVE-2025-14814MEDIUMCSS & JavaScript Toolbox <= 12.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via cjtoolbox ShortcodeEPSS 0.2%CVE-2026-97732MEDIUMIRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client executables by checking for expected publisher and EPSS 0.1%CVE-2026-97731HIGHMinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied X-Amz-SignedHeadersEPSS 0.2%CVE-2026-97730HIGHIn Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) wiEPSS 1.0%CVE-2026-97650MEDIUMningzichun student-management-system addLog.php echo cross site scriptingEPSS 0.3%CVE-2026-97724MEDIUMA prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker-controlled object containing EPSS 0.3%CVE-2026-97723MEDIUMmadpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (XSS) vulnerability in the chat message rendering functionality. User-coEPSS 0.2%CVE-2026-97649MEDIUMningzichun student-management-system example_lite.sql default credentialsEPSS 0.2%CVE-2026-95811MEDIUMLemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict itEPSS 0.4%CVE-2026-97648MEDIUMningzichun student-management-system cross-site request forgeryEPSS 0.2%CVE-2026-97647MEDIUMningzichun student-management-system editLog.php authorizationEPSS 0.3%CVE-2026-92289CRITICALLemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secretEPSS 0.4%CVE-2026-97646MEDIUMningzichun student-management-system getStudent.php authorizationEPSS 0.3%CVE-2026-92288CRITICALLemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying PartyEPSS 0.4%