Busca de CVEs

375.173 resultados
CVE-2026-10034MEDIUMWP DSGVO Tools (GDPR) <= 3.1.39 - Missing Authorization to Unauthenticated Sensitive Personal Data Disclosure via subject-access-request AJAX Endpoint (process_now/is_ajax Parameters)EPSS 0.6%CVE-2026-8713CRITICALAvada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion via Form Entry ValueEPSS 2.7%CVE-2026-8118MEDIUMRoyal Addons for Elementor – Addons and Templates Kit for Elementor 1.7.1058 - 1.7.1059 - Authenticated (Contributor+) Arbitrary File Read via Data Table Widget CSV File SourceEPSS 0.4%CVE-2026-11989MEDIUMBit integrations <= 2.8.7 - Unauthenticated Server-Side Request Forgery via Form Field Upload MappingEPSS 0.5%CVE-2026-4328MEDIUMAdvanced Import: One-Click Demo Import for WordPress <= 1.4.6 - Authenticated (Author+) Server-Side Request Forgery via 'demo_file' ParameterEPSS 0.3%CVE-2026-9013MEDIUMBogo <= 3.9.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via REST APIEPSS 0.4%CVE-2026-12157MEDIUMBetterDocs <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'blockId' Block AttributeEPSS 0.3%CVE-2026-7547MEDIUMWoosa <= 2.0.5 - Authenticated (Administrator+) Arbitrary File Read via 'log_file' ParameterEPSS 0.6%CVE-2026-1856MEDIUMAppointment Booking Calendar <= 1.4.4 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Booking Field LabelEPSS 0.3%CVE-2026-11752MEDIUMA vulnerability has been identified in armeria-xds versions 1.38.0 through 1.39.0, where DataSourceStream in the xDS module can resolve contEPSS 0.3%CVE-2026-10779MEDIUMClassified Listing <= 5.4.2 - Missing Authorization to Authenticated (Subscriber+) Feature Modification via Multiple AJAX Handlers ('listingId'/'id' Parameters)EPSS 0.4%CVE-2026-56132MEDIUMIn libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is misEPSS 0.1%CVE-2026-56131MEDIUMlibexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. TEPSS 0.1%CVE-2026-8806HIGHDenial-of-service (DoS) vulnerability in MELSEC iQ-F Series FX5-ENET/IP Ethernet moduleEPSS 0.6%CVE-2026-11775MEDIUMUser Admin Simplifier <= 3.0.0 - Cross-Site Request ForgeryEPSS 0.2%CVE-2026-8805HIGHDenial-of-service (DoS) vulnerability in MELSEC iQ-F Series EtherNet/IP moduleEPSS 0.6%CVE-2026-51844CRITICALTenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter.EPSS 0.4%CVE-2026-51843CRITICALTenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter.EPSS 0.4%CVE-2026-51845CRITICALTenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter.EPSS 0.4%CVE-2025-62821CRITICALMicrosoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving tEPSS 1.1%