Busca de CVEs

375.173 resultados
CVE-2026-48981MEDIUMpam_usb: xmlReadFile flags=0 permits XXE network entity fetching in conf.cEPSS 0.2%CVE-2026-48716HIGHnanobot: Path traversal via unsanitized WhatsApp document fileName enables arbitrary file writeEPSS 0.4%CVE-2026-47846CRITICALBitnami Cassandra container images are affected by a retained default superuser vulnerability. When a custom administrator account is configEPSS 0.5%CVE-2026-47847MEDIUMBitnami MariaDB Galera container images and Helm chart are affected by a hardcoded default credential vulnerability in the Galera replicatioEPSS 0.3%CVE-2026-12390HIGHAccess of resource using incompatible type ('type confusion') in AzeoTech DAQFactoryEPSS 0.1%CVE-2026-47833MEDIUMsetupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A compromised process insiEPSS 0.2%CVE-2026-48937MEDIUMA flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affectsEPSS 0.5%CVE-2026-55392MEDIUMNILFS utilities - Undefined Behavior and Out-of-Memory via Unvalidated s_log_block_sizeEPSS 0.2%CVE-2026-9692MEDIUMMojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurelyEPSS 0.4%CVE-2026-54390CRITICALJTL Shop < 5.7.2 Server-Side Template Injection via Smarty RendererEPSS 0.6%CVE-2026-48985MEDIUMpam_usb: NULL Dereference Crash in pusb_is_loginctl_local when loginctl Returns Empty Remote FieldEPSS 0.2%CVE-2026-48986MEDIUMpam_usb: Infinite loop DoS in process-tree walk when parent process exits during authenticationEPSS 0.1%CVE-2026-48984MEDIUMpam_usb: xfree() does not call explicit_bzero — sensitive cryptographic material may linger in freed heapEPSS 0.1%CVE-2025-53114HIGHCometD has acknowledgement extension out of memoryEPSS 0.7%CVE-2026-11982MEDIUMStored XSS via missing XSS safety check in Admin2 Pages API partial validationEPSS 0.5%CVE-2026-55237HIGHAutoGPT SignUp Page has DOM-Based XSS and Open RedirectEPSS 0.3%CVE-2026-48617LOWA flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confideEPSS 0.2%CVE-2025-32437HIGHAutoGPT has a DoS vulnerability in MediaDurationBlockEPSS 0.4%CVE-2025-32436HIGHAutoGPT has a DoS vulnerability in AddAudioToVideoBlockEPSS 0.4%CVE-2025-32424HIGHAutoGPT has a DoS vulnerability in ScreenshotWebPageBlockEPSS 0.4%