Busca de CVEs
375.184 resultadosCVE-2026-12449HIGHUse after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-level privilege escaEPSS 0.1%CVE-2026-12448HIGHInappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to perform privilege eEPSS 0.3%CVE-2026-12447HIGHHeap buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code inside a sandboxEPSS 0.4%CVE-2026-12446MEDIUMInappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to leak cross-origin data via aEPSS 0.2%CVE-2026-12445HIGHUse after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to install a malicious extensEPSS 0.2%CVE-2026-12444MEDIUMOut of bounds read in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to obtain potentially sensitivEPSS 0.1%CVE-2026-12443HIGHUse after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafEPSS 0.6%CVE-2026-12442HIGHUse after free in Passwords in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crEPSS 0.4%CVE-2026-12441HIGHUse after free in File Input in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruptEPSS 0.3%CVE-2026-12440CRITICALUse after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to potentially perform a EPSS 0.3%CVE-2026-12439HIGHUse after free in Digital Credentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruptEPSS 0.3%CVE-2026-12438HIGHInappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker who had compromised thEPSS 0.2%CVE-2026-12437HIGHUse after free in WebShare in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer prEPSS 0.3%CVE-2025-15641MEDIUMNetskope Client Exposed IOCTL with Insufficient Access ControlsEPSS 0.2%CVE-2026-55706MEDIUMsppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values for lengths.EPSS 0.4%CVE-2025-66391HIGHIn Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., theEPSS 0.4%CVE-2026-39199LOWsnes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.EPSS 0.1%CVE-2025-26240HIGHIn JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server applicatioEPSS 0.4%CVE-2026-36418CRITICALJimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressions. The /jmreport/eEPSS 0.5%CVE-2026-48797CRITICALBackpropagate: backprop ui --auth and backprop ui --share do not enforce authenticationEPSS 0.3%