Busca de CVEs
375.173 resultadosCVE-2026-56142CRITICALIn JetBrains Hub before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 privilege escalation by attaEPSS 0.6%CVE-2026-56141CRITICALIn JetBrains Hub before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 account takeover via predictEPSS 0.5%CVE-2026-53915HIGHIn JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configurationEPSS 0.3%CVE-2026-12706MEDIUMFfmpeg: ffmpeg: heap use-after-free read in rasc decoder decode_move()EPSS 0.2%CVE-2026-11941MEDIUMUse-after-free in connection ID iterator and FFI functionsEPSS 0.3%CVE-2026-41156HIGHGPU DDK - kernel<->fw CCB contains SYNC_PRIMITIVE_BLOCK firmware address without holding referenceEPSS 0.2%CVE-2026-34192HIGHGPU DDK - _MMU_AllocLevel error recovery paths leave dangling page table entriesEPSS 0.2%CVE-2026-8296MEDIUMIn affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts.EPSS 0.3%CVE-2026-11576HIGHThe security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanEPSS 0.5%CVE-2026-56138MEDIUMAuthenticated Path Traversal in AIL framework /objects/item/diff Allows Reading Gzip-Compressed FilesEPSS 0.5%CVE-2026-46461HIGHDell Server Hardware Manager, versions prior to 3.2.2, contains an Improper Access Control vulnerability. A low privileged attacker with locEPSS 0.1%CVE-2026-6798MEDIUM2Download Connector for 2DL Hosted Checkout <= 0.1.5 - Missing Authorization to Unauthenticated Sensitive Customer Subscription Data Exposure via 'ToDownload_email' ParameterEPSS 0.5%CVE-2026-3640MEDIUMSTRABL <= 4.5 - Unauthenticated Arbitrary Webhook Creation via REST API EndpointEPSS 0.6%CVE-2026-9822MEDIUMWP Hotel Booking < 2.3.1 - Subscriber+ Missing Authorization in Multiple AJAX HandlersEPSS 0.3%CVE-2026-54414CRITICALFileRise shared-folder upload path traversal allows arbitrary file write and admin takeoverEPSS 1.1%CVE-2026-7515CRITICALBetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_styleEPSS 0.9%CVE-2025-7737HIGHDoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage PlatformEPSS 0.5%CVE-2026-12644MEDIUMVersions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of built-in Object.protoEPSS 0.5%CVE-2026-10720MEDIUMMicroCeph path traversal issue in the remote-import APIEPSS 0.3%CVE-2026-12430MEDIUMBlocksy Companion <= 2.1.45 - Authenticated (Editor+) Stored Cross-Site Scripting via 'product_description' ParameterEPSS 0.3%