Busca de CVEs

375.173 resultados
CVE-2026-53539HIGHPython-Multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of serviceEPSS 0.4%CVE-2026-54285MEDIUMopentelemetry-js: Unbounded memory allocation in W3C Baggage propagationEPSS 0.3%CVE-2026-55388HIGHpiscina: Prototype Pollution Gadget → RCE via inherited options.filenameEPSS 0.5%CVE-2026-54283HIGHStarlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoSEPSS 0.4%CVE-2026-54282LOWStarlette: Unvalidated request path concatenated into authority poisons request.url.hostnameEPSS 0.2%CVE-2026-54273MEDIUMAIOHTTP: HTTP/1 Pipelined Requests Queue Without LimitEPSS 0.3%CVE-2026-54280LOWAIOHTTP: Payload Response Resources Are Not Closed After Mid-Body DisconnectEPSS 0.3%CVE-2026-54278MEDIUMAIOHTTP: Unread Compressed Request Bodies Bypass client_max_size During CleanupEPSS 0.4%CVE-2026-54277MEDIUMAIOHTTP: C HTTP Parser Bypasses max_line_size for Fragmented LinesEPSS 0.3%CVE-2026-54276MEDIUMAIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect ChallengesEPSS 0.2%CVE-2026-54275LOWAIOHTTP: TLS Server Hostname Override Is Ignored When Reusing HTTPS ConnectionsEPSS 0.3%CVE-2026-54274MEDIUMAIOHTTP: Incomplete websocket frame payloads bypass memory limitsEPSS 0.3%CVE-2026-54279LOWAIOHTTP: Host-Only Cookies Become Domain Cookies After CookieJar PersistenceEPSS 0.3%CVE-2026-42127HIGHPre-authentication denial of service in the public dashboard query endpointEPSS 0.4%CVE-2026-50269LOWAIOHTTP: CRLF injection in multipart headersEPSS 0.3%CVE-2026-54269MEDIUMprotobufjs: Schema-derived names can shadow runtime-significant propertiesEPSS 0.4%CVE-2026-48712HIGHprotobufjs: Denial of service through unbounded Any expansion during JSON conversionEPSS 0.5%CVE-2026-54270MEDIUMprotobufjs: Memory amplification from preserved unknown fields in binary decodeEPSS 0.4%CVE-2026-54271HIGHprotobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor namesEPSS 0.3%CVE-2026-53571HIGHVite: `server.fs.deny` bypass on Windows alternate pathsEPSS 0.6%