Busca de CVEs
375.173 resultadosCVE-2026-44273MEDIUMDell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high privileged attackerEPSS 0.1%CVE-2026-44274HIGHDell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vulnerability. A low prEPSS 0.1%CVE-2026-53779HIGHWebP Server Go < 0.15.0 Path Traversal via Backslash Encoding on WindowsEPSS 0.6%CVE-2026-11834HIGHUnauthenticated Command Injection via DHCP Option Handling in Multiple TP-Link RoutersEPSS 1.0%CVE-2026-53663LOWReact Router: `handleDocumentRequest` CSRF check covers `POST` only; PUT/PATCH/DELETE bypassEPSS 0.1%CVE-2026-54299HIGHAstro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)EPSS 0.3%CVE-2026-54298MEDIUMAstro: XSS via Unescaped Attribute Names in Spread PropsEPSS 0.2%CVE-2026-50146HIGHAstro: Reflected XSS via unescaped slot nameEPSS 0.3%CVE-2026-54300MEDIUM@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN configEPSS 0.3%CVE-2026-54293HIGHNLTK: URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File ReadEPSS 0.6%CVE-2026-55443MEDIUMLangChain: Path traversal and sandbox escape in LangChain file-search middleware and loadersEPSS 0.2%CVE-2026-54288MEDIUMHono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`EPSS 0.1%CVE-2026-54289MEDIUMHono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the restEPSS 0.2%CVE-2026-54290HIGHHono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcardEPSS 0.3%CVE-2026-10789CRITICALMCP Extension Code Injection Vulnerability in Autodesk Fusion DesktopEPSS 0.7%CVE-2026-54286MEDIUMHono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)EPSS 0.4%CVE-2026-54287MEDIUMHono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and LatticeEPSS 0.3%CVE-2026-53540LOWPython-Multipart: Negative Content-Length in parse_form buffers the entire body in memoryEPSS 0.2%CVE-2026-53537LOWPython-Multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parametersEPSS 0.2%CVE-2026-53538LOWPython-Multipart: Semicolon treated as querystring field separator enables parameter smugglingEPSS 0.2%