Busca de CVEs
375.173 resultadosCVE-2026-28381CRITICALLocal File Read/Write to Potential Privilege Escalation via Snowflake GET/PUTEPSS 0.2%CVE-2025-33128MEDIUMIBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities HTML / XSS Injection observedEPSS 0.2%CVE-2025-2669MEDIUMMultiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.EPSS 0.2%CVE-2026-9029HIGHStored XSS in the Geomap panel tile-layer attributionEPSS 0.3%CVE-2026-10601MEDIUMPath traversal in the Tempo and Loki data source pluginsEPSS 0.3%CVE-2026-42129HIGHPath traversal in the Loki data source pluginEPSS 0.4%CVE-2024-54178MEDIUMMultiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.EPSS 0.4%CVE-2026-12888LOWHTML injection in the Canarytoken Google Chat notificationEPSS 0.4%CVE-2026-56450MEDIUMAIL Framework - Missing Rate Limiting Enables Brute-Force Attacks Against Two-Factor Authentication CodesEPSS 0.6%CVE-2026-56448HIGHAuthenticated Path Traversal in AIL Framework Investigation Downloads Allows Arbitrary File ReadEPSS 0.4%CVE-2026-7167MEDIUMMultiple vulnerabilities in the Assassin game by GaudireEPSS 0.6%CVE-2026-7166CRITICALMultiple vulnerabilities in the Assassin game by GaudireEPSS 0.5%CVE-2026-7165CRITICALMultiple vulnerabilities in the Assassin game by GaudireEPSS 0.5%CVE-2026-54100HIGHWindows-machine-config-operator: windows-machine-config-operator: ssh host key not verified enables credential theftEPSS 0.3%CVE-2026-54099HIGHWindows-machine-config-operator: windows-machine-config-operator: wicd csr extra-organization allows privilege escalation to system:mastersEPSS 0.1%CVE-2026-6653HIGHlibxml2: Use after free in xmlParseInternalSubset via improper entity resolution handlingEPSS 0.4%CVE-2026-56447CRITICALMISP remote code execution via arbitrary rdkafka configuration pathEPSS 0.3%CVE-2026-12602HIGHIncorrect permissions in ArubaSign by ArubaEPSS 0.2%CVE-2026-56446HIGHAuthenticated Remote Code Execution via Arbitrary NDJSON Error Log Path in MISPEPSS 0.4%CVE-2026-56425CRITICALMISP AAD authentication plugin - Improper OAuth State Handling, Missing Session Rotation, Insecure Redirect URI Validation, and Log InjectionEPSS 0.3%