Busca de CVEs
375.173 resultadosCVE-2026-48794LOWAuthelia has an Edge Case Access Control Rule MismatchEPSS 0.3%CVE-2026-47203LOWAuthelia Missing Username Canonicalization in Basic Auth (LDAP)EPSS 0.5%CVE-2026-48129MEDIUMKestra task inputFiles accepts traversal filenames for worker file writesEPSS 0.4%CVE-2026-49346HIGHlibde265 has a heap buffer overflow in de265_image_get_buffer via SPS dimension integer overflowEPSS 0.2%CVE-2026-49295HIGHlibde265 has an out-of-bounds write in process_reference_picture_set via predicted short-term RPSEPSS 0.2%CVE-2026-49337MEDIUMlibde265 has an unbounded memory leak via orphaned slice headers in `read_slice_NAL`EPSS 0.2%CVE-2026-48787HIGHgin-vue-admin vulnerable to RCEEPSS 0.7%CVE-2026-48089HIGHDevGuard has improper authorization on public assetsEPSS 0.4%CVE-2026-48774HIGHProxySQL MCP run_sql_readonly executes side-effecting MySQL multi-statements despite read-only contractEPSS 0.4%CVE-2026-48772CRITICALProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql_query_rules.client_addr ACLEPSS 0.2%CVE-2026-48773CRITICALProxySQL pre-auth heap overflow in MySQL and PostgreSQL first-packet handlingEPSS 0.7%CVE-2026-49345MEDIUMMercator CVE Configuration Vulnerable to Server-Side Request Forgery (SSRF)EPSS 0.6%CVE-2026-49344HIGHMercator has a Personal Identifiable Information Leak from Query Executor featureEPSS 0.4%CVE-2026-48715HIGHradvdump's Route Information Option Parser has a Stack Buffer OverflowEPSS 0.2%CVE-2026-49342MEDIUMYARD static cache reads raw traversal paths before router sanitizationEPSS 0.4%CVE-2026-49340HIGHgonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the hostEPSS 0.4%CVE-2026-49338HIGHSubsonic API: any authenticated user can delete or read any other user's playlist (IDOR)EPSS 0.3%CVE-2026-27878MEDIUMTempo TraceQL query with exemplar hint could result in unbounded memory usageEPSS 0.4%CVE-2026-12726MEDIUMAwx: automation-controller: awx: github webhook second-order ssrf via unvalidated statuses_url exfiltrates pat credentialEPSS 0.3%CVE-2026-9375HIGHDecompression Bomb Bypass via Negative max_length in Streaming API in urllib3EPSS 0.3%