Busca de CVEs

375.173 resultados
CVE-2026-55409HIGHFilament: Disabled RichEditor field state can be used for XSSEPSS 0.3%CVE-2026-48067MEDIUMFilament: Inconsistent scope enforcement for AttachAction and AssociateAction Select fieldsEPSS 0.3%CVE-2026-48167MEDIUMFilament: Unvalidated ImageColumn and ImageEntry values can be used for XSSEPSS 0.2%CVE-2026-48500MEDIUMFilament: Unauthenticated temporary file upload on auth pagesEPSS 0.3%CVE-2026-48166MEDIUMFilament: Timing-based user enumeration on login pageEPSS 0.3%CVE-2026-48505HIGHFilament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submissionEPSS 0.3%CVE-2026-44889MEDIUMWebOb: Location header normalization during redirect leads to open redirectEPSS 0.2%CVE-2026-48109HIGHMessagePack-CSharp: LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad inputEPSS 0.5%CVE-2026-48502HIGHMessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflowsEPSS 0.3%CVE-2026-48506HIGHMessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depthEPSS 0.5%CVE-2026-48509MEDIUMMessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodiesEPSS 0.3%CVE-2026-48510MEDIUMMessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengthsEPSS 0.2%CVE-2026-48511MEDIUMMessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted mapsEPSS 0.2%CVE-2026-48512MEDIUMMessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcementEPSS 0.2%CVE-2026-48513MEDIUMMessagePack-CSharp: DynamicUnionResolver generated deserializers miss depth enforcementEPSS 0.2%CVE-2026-48514MEDIUMMessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte lengthEPSS 0.2%CVE-2026-48515MEDIUMMessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensionsEPSS 0.2%CVE-2026-48516MEDIUMMessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settingsEPSS 0.2%CVE-2026-56698MEDIUMNuxt - Cross-Site Scripting via navigateTo open OptionEPSS 0.4%CVE-2026-56697MEDIUMNuxt - Open Redirect via Protocol-Relative Paths in reloadNuxtAppEPSS 0.3%