Busca de CVEs

400.010 resultados
CVE-2026-100884MEDIUMKrayin laravel-crm attachment-download Endpoint acl.php resource injectionEPSS 0.5%CVE-2026-100883MEDIUMKrayin laravel-crm acl.php access controlEPSS 0.5%CVE-2026-96284LOWFlatpak: flatpak: arbitrary read-access to files in the system-helper context via oci symlink followingEPSS 0.1%CVE-2026-100882MEDIUMKrayin laravel-crm Admin Settings Endpoint index.blade.php cross site scriptingEPSS 0.3%CVE-2026-96282LOWFlatpak: flatpak: extension metadata path traversal file existence oracleEPSS 0.3%CVE-2026-96283LOWFlatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another user's ongoing pullEPSS 0.1%CVE-2026-100881LOWzhistaredu StarTraining application.yml cross site scriptingEPSS 0.2%CVE-2026-96281MEDIUMFlatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimesEPSS 0.2%CVE-2026-100880MEDIUMzhistaredu StarTraining Upload Endpoint MimeTypeUtils.java cross site scriptingEPSS 0.2%CVE-2026-101090CRITICALNezha through 2.2.3 Host Header Injection via OAuth2 redirect_uriEPSS 0.4%CVE-2026-101089LOWNezha before 2.2.7 Information Disclosure via /api/v1/profileEPSS 0.2%CVE-2026-101088MEDIUMNezha before 2.3.1 Denial of Service via Concurrent Server DeleteEPSS 0.2%CVE-2026-101087MEDIUMNezha 2.0.10 through 2.3.2 SSRF Denylist Bypass IPv6EPSS 0.3%CVE-2026-101086HIGHNezha Dashboard before 2.3.5 Task Type Validation BypassEPSS 0.3%CVE-2026-101085HIGHNezha before 2.3.8 Denial of Service via Alert RuleEPSS 0.2%CVE-2026-101084CRITICALobot before v0.21.1 Authorization Bypass via /mcp-connectEPSS 0.3%CVE-2026-101065CRITICALObot Quickstart Docker Deployment Unauthenticated Admin AccessEPSS 0.4%CVE-2026-101064HIGHObot before v0.23.0 Server-Side Request Forgery via MCPEPSS 0.2%CVE-2026-101063MEDIUMObot before v0.23.0 Authentication Bypass via Registry APIEPSS 0.2%CVE-2026-101062HIGHObot before v0.23.0 Authentication Bypass via OAuth Dynamic Client RegistrationEPSS 0.3%