Busca de CVEs

375.173 resultados
CVE-2025-59563HIGHWordPress Sonaar theme <= 4.27.4 - Privilege Escalation vulnerabilityEPSS 0.4%CVE-2025-59560HIGHWordPress Sonaar theme <= 4.27.4 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-58954HIGHWordPress HomeRoofer theme <= 2.11.0 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2025-58953HIGHWordPress Joly theme <= 1.22.0 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2025-58952HIGHWordPress Neuronet theme < 1.14.0 - Local File Inclusion vulnerabilityEPSS 0.3%CVE-2025-49403HIGHWordPress Premium Age Verification / Restriction for WordPress Plugin <= 3.0.2 - Arbitrary File Download VulnerabilityEPSS 0.3%CVE-2024-52488CRITICALWordPress Grip theme <= 1.0.9 - Arbitrary Plugin Activation/Deactivation to RCE vulnerabilityEPSS 0.5%CVE-2024-49269HIGHWordPress my flatonica theme <= 0.0.8 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-12165HIGHContest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' ParameterEPSS 0.4%CVE-2026-12115MEDIUMCounter Box <= 2.0.13 - Authenticated (Administrator+) PHP Object Injection via ImportEPSS 0.5%CVE-2026-47340MEDIUMApache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.EPSS 0.4%CVE-2026-32967MEDIUMApache DolphinScheduler: The `/v2` experimental interface lacks permission checksEPSS 0.3%CVE-2026-42357MEDIUMApache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.EPSS 0.3%CVE-2026-41280MEDIUMApache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projectsEPSS 0.4%CVE-2026-32966HIGHApache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata DisclosureEPSS 0.4%CVE-2026-40722MEDIUMWordPress Yoast SEO Premium plugin <= 26.6 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-27869MEDIUMWEB SERVICE (HTTP) DENIAL OF SERVICE VIA SLOW HEADERS ON REGESTA SMART HD-PLC OF TELDATEPSS 0.4%CVE-2026-27870MEDIUMCROSS-SITE SCRIPTING (XSS) VIA MALICIOUS FILE UPLOAD ON REGESTA SMART HD-PLC OF TELDATEPSS 0.3%CVE-2026-27868MEDIUMPUBLICATION OF SENSITIVE INFORMATION ON REGESTA SMART HD-PLC OF TELDATEPSS 0.4%CVE-2026-0063CRITICALIn setAllowedCarriers of PhoneInterfaceManager.java, there is a possible way to disable carrier restrictions due to a logic error in the codEPSS 0.2%