Busca de CVEs
375.184 resultadosCVE-2026-11358MEDIUMOrbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More <= 3.0.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu-item-icon' ParameterEPSS 0.3%CVE-2026-11402MEDIUMServices Section Block <= 1.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Block AttributeEPSS 0.2%CVE-2026-11784MEDIUMOptimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.6 - Cross-Site Request Forgery via 'optml_replace_file' AJAX ActionEPSS 0.2%CVE-2026-12093MEDIUMSimple Membership <= 4.7.5 - Missing Authorization to Unauthenticated Arbitrary Member Account Deactivation via Forged Stripe 'charge.refunded' WebhookEPSS 0.4%CVE-2026-10736MEDIUMTutor LMS <= 3.9.11 - Authenticated (Administrator+) SQL Injection via 'data' ParameterEPSS 0.5%CVE-2026-10623MEDIUMPressPrimer Quiz <= 2.3.0 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Modification via 'quiz_id', 'item_id', and 'rule_id' ParametersEPSS 0.3%CVE-2026-11360MEDIUMAdvanced Order Export For WooCommerce <= 4.0.10 - Authenticated (Shop Manager+) SQL Injection via 'sort_direction' ParameterEPSS 0.5%CVE-2026-11357MEDIUMKadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData LocalizationEPSS 0.3%CVE-2026-11776MEDIUMForm Maker by 10Web <= 1.15.43 - Authenticated (Adminsitrator+) SQL Injection via 'groupids' ParameterEPSS 0.3%CVE-2026-10029MEDIUMEvent Koi Lite <= 1.3.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via REST API EndpointsEPSS 0.3%CVE-2026-9860HIGHOffload, AI & Optimize with Cloudflare Images <= 1.10.2 - Authenticated (Author+) Remote Code Execution via 'api-key' / 'account-id' Parameters in cf_images_do_setup AJAX ActionEPSS 0.6%CVE-2026-12120MEDIUMFireBox Popups <= 3.1.7 - Unauthenticated Sensitive Information Exposure in 'form_id' ParameterEPSS 0.3%CVE-2026-11777MEDIUMForm Maker by 10Web <= 1.15.43 - Authenticated (Administrator+) SQL Injection via 'name' ParameterEPSS 0.3%CVE-2026-9199MEDIUMEqualize Digital Accessibility Checker <= 1.42.1 - Missing Authorization to Authenticated (Author+) Arbitrary Accessibility Issue Modification via 'largeBatch' ParameterEPSS 0.2%CVE-2026-12407HIGHE2Pdf <= 1.32.26 - Missing Authorization to Authenticated (Custom+) Arbitrary Option Update / Privilege Escalation via 'screen_action' ParameterEPSS 0.4%CVE-2026-10023MEDIUMDokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.3 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Order Modification via Multiple AJAX HandlersEPSS 0.2%CVE-2026-12505HIGHCifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcallEPSS 0.2%CVE-2026-12569CRITICALRemote Code Execution (RCE) vulnerability in Windchill PDMlinkEPSS 30.2%KEVCVE-2026-38718HIGHInHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a buffer overflow vulnerEPSS 0.5%CVE-2026-38717CRITICALInHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnEPSS 2.3%