Busca de CVEs
375.173 resultadosCVE-2026-54281HIGHNest: Middleware Bypass on Fastify via Trailing SlashEPSS 0.5%CVE-2026-49468CRITICALLiteLLM: Authentication Bypass via Host Header InjectionEPSS 0.6%CVE-2026-41479MEDIUMAuthlib OAuth 2.0 authorization endpoint open redirects to attacker-controlled redirect_uri on unsupported response_typeEPSS 0.2%CVE-2026-45034CRITICALPhpSpreadsheet: File::prohibitWrappers bypassEPSS 0.4%CVE-2026-54651MEDIUMpypdf: Possible infinite loop when processing threads/articles in writerEPSS 0.1%CVE-2026-49460MEDIUMpypdf: Inefficient decoding of FlateDecode PNG predictor streamsEPSS 0.1%CVE-2026-49461MEDIUMpypdf: Possible large memory usage for form XObjects during text extractionEPSS 0.1%CVE-2026-54531MEDIUMpypdf: Possible infinite loop when processing outlines/bookmarks in writerEPSS 0.1%CVE-2026-54530MEDIUMpypdf: Possible infinite loop when retrieving fonts for layout-mode text extractionEPSS 0.1%CVE-2026-47242MEDIUMNet::IMAP: Command Injection via ID command argumentEPSS 0.1%CVE-2026-47240MEDIUMNet::IMAP: Command Injection via non-synchronizing literal in "raw" argumentEPSS 0.5%CVE-2026-39904HIGHGophish 0.12.1 Denial of Service via Office Document UploadEPSS 0.4%CVE-2026-47241LOWNet::IMAP: Denial of Service via incomplete raw argument validationEPSS 0.2%CVE-2026-55603HIGHhttp-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`EPSS 0.3%CVE-2026-55599MEDIUMphpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority Information AccessEPSS 0.2%CVE-2026-44727CRITICALJupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSPEPSS 0.3%CVE-2026-10852MEDIUMWebsphere Application Server is Affected By a Denial of ServiceEPSS 0.3%CVE-2026-44271HIGHDell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command EPSS 0.3%CVE-2026-48931LOWA flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request.
This vEPSS 0.3%CVE-2026-44272HIGHDell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command EPSS 0.3%