Busca de CVEs

375.173 resultados
CVE-2026-56267MEDIUMFlowise - PII Disclosure via Unauthenticated Forgot Password EndpointEPSS 0.5%CVE-2026-56235MEDIUMCapgo - Unauthenticated Cross-Tenant Metrics Disclosure via RPC FunctionsEPSS 0.4%CVE-2026-56228MEDIUMCapgo - Denial of Service via Improper Password Policy Length ValidationEPSS 0.5%CVE-2026-56227MEDIUMCapgo - Server-Side Request Forgery via Webhook URL ValidationEPSS 0.3%CVE-2026-56218MEDIUMCapgo - EXIF Metadata Exposure via Image UploadEPSS 0.3%CVE-2025-71331MEDIUMFlowise - Cross-Site Scripting in Chat Messages and Agent WorkflowsEPSS 0.2%CVE-2026-56325LOWCapgo - App ID Confusion via ILIKE Wildcard in Preview Subdomain LookupEPSS 0.3%CVE-2026-56317LOWNuxt - Cross-Site Scripting via NoScript Component Slot ContentEPSS 0.2%CVE-2024-58351CRITICALFlowise - Remote Code Execution via overrideConfig ParameterEPSS 0.9%CVE-2022-50972CRITICALWooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.phpEPSS 1.1%CVE-2020-37255HIGHWordPress Time Capsule Plugin 1.21.16 Authentication BypassEPSS 0.6%CVE-2019-25763CRITICALWordPress Ultimate Addons for Beaver Builder 1.2.4.1 Authentication BypassEPSS 0.8%CVE-2026-12673MEDIUMLiquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalation from an Admin in EPSS 0.4%CVE-2026-48908CRITICALJoomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2EPSS 88.1%CVE-2026-48939CRITICALJoomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15EPSS 82.5%KEVCVE-2026-48909CRITICALJoomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4EPSS 7.6%CVE-2026-12119MEDIUMSimple File List <= 6.3.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode AttributeEPSS 0.5%CVE-2026-11911HIGHSimple File List <= 6.3.7 - Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' ParameterEPSS 1.2%CVE-2026-11912HIGHSimple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX ActionEPSS 0.5%CVE-2026-9843HIGHDatabase for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Deletion via CF7 File Field POST ValueEPSS 0.9%