Busca de CVEs

375.173 resultados
CVE-2026-8668LOWHardcoded credentials in embedded contentEPSS 0.3%CVE-2026-8100HIGHImpact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints under specific condEPSS 0.5%CVE-2026-49205MEDIUMphpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)EPSS 0.4%CVE-2026-54017HIGHOpen WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversalEPSS 0.5%CVE-2026-22674MEDIUMHashgraph Guardian Stored XSS via branding companyName fieldEPSS 0.3%CVE-2026-49257CRITICALmcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bindEPSS 0.9%CVE-2026-49454CRITICALRelyra SAML SignatureValue not cryptographically verified -> authentication bypassEPSS 0.2%CVE-2026-46699HIGHconda-smithy vulnerable to misrouted repository invitation by conda-forge-webservices[bot] due to GitHub username takeover leading to unintended write access in conda-forge feedstock repositoryEPSS 0.3%CVE-2026-45696HIGHOpenEXR HTJ2K decoder heap buffer over-read in ht_undo_impl() (DoS)EPSS 0.3%CVE-2026-44663MEDIUMOpenEXR: Integer overflow in the HTJ2K decoder leads to heap-buffer-overflowEPSS 0.2%CVE-2025-15661HIGHlibssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.cEPSS 1.0%CVE-2026-49252CRITICALdeepstream is vulnerable to prototype pollutionEPSS 0.5%CVE-2026-49248HIGHOneDev: RCE through absolute-path symlink following allows low-privileged users to overwrite arbitrary server via TarUtils.untarEPSS 0.6%CVE-2026-43994HIGHCoturn: Stack buffer overflow in decode_oauth_token_gcm()EPSS 0.4%CVE-2026-25865HIGHPunto Switcher 4.5.0.583 Unquoted Search Path via WinExecEPSS 0.2%CVE-2026-43915MEDIUMCoturn: Stored Cross-Site Scripting (XSS) in web-admin interface via TURN usernameEPSS 0.2%CVE-2026-56099MEDIUMOpenBSD mpls_do_error Kernel Stack Memory Disclosure via MPLS InputEPSS 0.4%CVE-2026-48980MEDIUMpam_usb: getenv() used in PAM context allows environment variable injection into local-check logicEPSS 0.2%CVE-2026-48983MEDIUMpam_usb: TOCTOU race condition in pad directory creation allows symlink substitutionEPSS 0.1%CVE-2026-48982MEDIUMpam_usb: Missing O_EXCL on pad temp file creation allows concurrent update raceEPSS 0.1%