Busca de CVEs

375.176 resultados
CVE-2026-37216MEDIUMRuoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add.EPSS 0.2%CVE-2026-36213HIGHAn issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.exe component.EPSS 0.6%CVE-2026-38060CRITICALTenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter.EPSS 1.0%CVE-2025-55661MEDIUMA heap buffer overflow in the Opus audio stream parser component of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) viaEPSS 0.3%CVE-2025-55650MEDIUMA heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial EPSS 0.2%CVE-2026-50879HIGHAn issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a craEPSS 0.3%CVE-2026-50890CRITICALBernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /stockreports/spendings.EPSS 0.3%CVE-2026-38064CRITICALTenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter.EPSS 1.0%CVE-2026-38062CRITICALTenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the ratMode parameter.EPSS 1.0%CVE-2026-30121CRITICALremotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.EPSS 0.3%CVE-2026-50881HIGHIncorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate privileges to AdminisEPSS 0.2%CVE-2026-50888HIGHAn authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows aEPSS 0.2%CVE-2026-39197MEDIUMAn issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Service (DoS) via a crafEPSS 0.3%CVE-2026-30120CRITICALremotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability.EPSS 0.8%CVE-2026-50871CRITICALAn OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attaEPSS 1.6%CVE-2026-50891HIGHIncorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafteEPSS 0.3%CVE-2026-50870HIGHAn information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attackers to obtain sensitivEPSS 0.3%CVE-2025-55644MEDIUMA heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial EPSS 0.2%CVE-2026-50875HIGHIncorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers to arbitrarily modiEPSS 0.3%CVE-2026-50872CRITICALAn issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtaEPSS 0.6%