Busca de CVEs

375.173 resultados
CVE-2026-47103CRITICALPython StateMachine 3.0.0 < 3.2.0 RCE via SCXML eval() InjectionEPSS 1.2%CVE-2026-49502HIGHDell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with aEPSS 0.2%CVE-2026-12528MEDIUM389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()EPSS 0.2%CVE-2026-54812CRITICALWordPress Motors plugin <= 1.4.109 - SQL Injection vulnerabilityEPSS 0.3%CVE-2026-22283HIGHDell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion of Functionality from Untrusted Control Sphere vulnerability. AEPSS 0.2%CVE-2026-54810HIGHWordPress Nexi XPay plugin <= 8.3.1 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-40641MEDIUMDell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthEPSS 0.1%CVE-2026-55748MEDIUMOpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharaEPSS 0.2%CVE-2024-47477MEDIUMDell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote unauthenticated attackEPSS 0.1%CVE-2026-55743CRITICALOpenHuman desktop agent shell tool sandbox bypass leads to arbitrary command executionEPSS 0.7%CVE-2026-54415HIGHBroken Access Control in Azuriom CMS Server Routes Allows Account TakeoverEPSS 0.3%CVE-2026-11311HIGHNGINX Gateway Fabric vulnerabilityEPSS 0.6%CVE-2026-48142MEDIUMNGINX ngx_http_charset_module vulnerabilityEPSS 0.7%CVE-2026-42055CRITICALNGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerabilityEPSS 4.0%CVE-2026-42530CRITICALNGINX Open-Source ngx_http_v3_module vulnerabilityEPSS 3.7%CVE-2026-48117MEDIUMDroneAware's Improper Account Activation in Registration and SSO Flows Leads to Account TakeoverEPSS 0.2%CVE-2026-54809CRITICALWordPress GIFT4U plugin <= 1.0.10 - SQL Injection vulnerabilityEPSS 0.2%CVE-2026-54808CRITICALWordPress WP Travel Gutenberg Blocks plugin <= 3.9.4 - SQL Injection vulnerabilityEPSS 0.3%CVE-2025-69189HIGHWordPress JobBank plugin <= 1.2.3 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2025-69128HIGHWordPress JobCareer theme <= 7.3 - Arbitrary File Deletion vulnerabilityEPSS 0.5%