Busca de CVEs
375.184 resultadosCVE-2026-11407HIGHPimcore CMS 12.3.8 Twig Sandbox Bypass via SecurityPolicy checkMethodAllowedEPSS 0.6%CVE-2026-48823MEDIUMShaarli has Stored Cross-Site Scripting (XSS) via Tags SearchEPSS 0.1%CVE-2026-32682HIGHNGINX Gateway Fabric vulnerabilityEPSS 0.3%CVE-2026-50107HIGHNGINX Gateway Fabric vulnerabilityEPSS 0.5%CVE-2026-48822MEDIUMShaarli has Stored Cross-Site Scripting (XSS) via Markdown Reference LinksEPSS 0.1%CVE-2026-54388CRITICALTinyproxy - HTTP Request Smuggling via Duplicate Content-Length HeadersEPSS 0.4%CVE-2026-54387CRITICALTinyproxy - HTTP Request Smuggling via CL/TE DesynchronizationEPSS 0.4%CVE-2026-48817MEDIUMStarlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`EPSS 0.2%CVE-2026-48814CRITICALNetwork-AI: Empty default secret still authorizes all requests (Incomplete fix for CVE-2026-46701)EPSS 0.3%CVE-2026-55202HIGHTinyproxy - Stathost Detection Bypass via Host Header ManipulationEPSS 0.4%CVE-2026-55201HIGHEvil-WinRM - Path Traversal in download_dir() FunctionEPSS 0.3%CVE-2026-55200CRITICALlibssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.cEPSS 2.0%CVE-2026-10741MEDIUMNexus Repository Manager - Incorrect Authorization allows credential disclosure via proxy repository configurationEPSS 0.3%CVE-2026-55199HIGHlibssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO HandlerEPSS 0.9%CVE-2026-10696HIGHUse of an incorrectly resolved name or reference in the pinget backend
in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet communiEPSS 0.3%CVE-2026-12529MEDIUMSourceCodester CET Automated Grading System with AI Predictive Analytics Student Self-Registration Endpoint index.php access controlEPSS 0.3%CVE-2026-55198HIGHHermes WebUI < 0.51.443 - Cross-Profile Session Data Exfiltration via Session Export EndpointEPSS 0.3%CVE-2026-55197HIGHHermes WebUI < 0.51.443 - Broken Access Control in /api/session EndpointEPSS 0.3%CVE-2026-55196CRITICALHermes WebUI < 0.51.409 - Unauthenticated Passkey Registration via Authentication BypassEPSS 0.6%CVE-2026-53871HIGHHermes WebUI < 0.51.368 - Profile-Scoped Authorization Bypass via Forged hermes_profile CookieEPSS 0.4%