Busca de CVEs

375.173 resultados
CVE-2024-27928MEDIUMVantage6: 2FA can be circumvented with hacked email accessEPSS 0.3%CVE-2026-44645MEDIUMLiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` bodyEPSS 0.3%CVE-2024-24769LOWVantage6: No limit on emails sent for password/MFA resetEPSS 0.3%CVE-2026-50268LOWSteeltoe: OAEP setting silently selects PKCS#1 v1.5 paddingEPSS 0.0%CVE-2026-50267MEDIUMSteeltoe: TLS private keys written to /tmp with default permissions, never deletedEPSS 0.1%CVE-2026-48759HIGHTypeBot: Cross-Workspace Theme Template IDOR (Modification and Deletion)EPSS 0.2%CVE-2026-12568MEDIUMArbitrary File Write in postman_download moduleEPSS 0.3%CVE-2026-50202MEDIUMSteeltoe's static JWKS cache shared across schemes and never invalidatedEPSS 0.3%CVE-2026-12567LOWSymlink-following arbitrary write via github_workflows moduleEPSS 0.1%CVE-2026-44644MEDIUMLiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSSEPSS 0.2%CVE-2026-12566LOWSSRF via unvalidated WWW-Authenticate realm in docker_pull moduleEPSS 0.2%CVE-2026-50201MEDIUMSteeltoe's sensitive actuators (heapdump/env) only require Restricted permissionEPSS 0.2%CVE-2026-12565MEDIUMPath Traversal (Zip-Slip) in unarchive moduleEPSS 0.2%CVE-2026-50200HIGHSteeltoe's env sanitizer misses connection strings — leaks embedded DB passwordsEPSS 0.2%CVE-2026-48997HIGHe107: Command Injection via shell expansion in ImageMagick resize destination pathEPSS 0.7%CVE-2026-54386MEDIUMmarimo < 0.23.9 XSS via file Query Parameter in assets.pyEPSS 0.2%CVE-2026-48991MEDIUMXianYuLauncher: Legacy Microsoft account OAuth sign-in flow lacks PKCE and state validationEPSS 0.1%CVE-2026-48820MEDIUMCakePHP: View::element() is missing a path containment checkEPSS 0.3%CVE-2026-50196HIGHSteeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetchEPSS 0.3%CVE-2026-48990MEDIUMjoserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserializationEPSS 0.2%