Busca de CVEs
381.637 resultadosCVE-2026-54714MEDIUMLogto: XSS via unescaped RelayState in SAML auto-submit formEPSS 0.3%CVE-2026-57850HIGHRustDesk Missing Session Scope Enforcement Allows Out-of-Scope Control Message InjectionEPSS 0.4%CVE-2026-57156HIGHFreeRDP: Integer overflow leading to heap buffer overflow in Orders Delta Points parsingEPSS 0.4%CVE-2026-57157MEDIUMOut-of-bounds read in the camera device enumerator server (rdpecam) via unterminated DeviceName / VirtualChannelNameEPSS 0.4%CVE-2026-57158MEDIUMFreeRDP planar_decompress_plane_rle_only: heap OOB read — incomplete fix for CVE-2026-23530EPSS 0.5%CVE-2026-55827HIGHFreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decodeEPSS 0.3%CVE-2026-55481MEDIUMSnipe-IT: CSS Injection via `header_color` SettingEPSS 0.2%CVE-2026-15295MEDIUMAjax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site ScriptingEPSS 0.2%CVE-2026-55475MEDIUMSnipe-IT: Import created_by can be overwrittenEPSS 0.2%CVE-2026-55469MEDIUMSnipe-IT: Path traversal vulnerability via CSV import `image` fieldEPSS 0.4%CVE-2026-55461MEDIUMSnipe-IT: Open Redirect After User EditEPSS 0.2%CVE-2026-55479MEDIUMSnipe-IT: Incorrect permission for legacy license checkin APIEPSS 0.2%CVE-2026-55452MEDIUMSnipe-IT: CSV formula injection in Activity Report exportEPSS 0.2%CVE-2026-55466MEDIUMSnipe-IT: Stored XSS via inline-served attachmentEPSS 0.3%CVE-2026-55515MEDIUMSnipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpointEPSS 0.3%CVE-2026-55462MEDIUMSnipe-IT: Authorization bypass on print inventory pageEPSS 0.3%CVE-2026-11321HIGHGLPI DataInjection Plugin Authenticated SQL Injection via CSV ImportEPSS 0.3%CVE-2026-55464MEDIUMSnipe-IT: Stored XSS via Markdown custom fieldEPSS 0.2%CVE-2026-55460HIGHSnipe-IT: Authorization bypass on bulk editing usersEPSS 0.3%CVE-2026-55472MEDIUMSnipe-IT: API Location Creation Bypasses FMCS Parent-Child Company Boundary ValidationEPSS 0.2%