Busca de CVEs
375.176 resultadosCVE-2026-50872CRITICALAn issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtaEPSS 0.6%CVE-2026-50892MEDIUMIncorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers EPSS 0.2%CVE-2026-50873CRITICALAn arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code vEPSS 0.4%CVE-2026-50869CRITICALAn issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted requestEPSS 0.7%CVE-2026-50874HIGHAn OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allows attackers to execEPSS 1.1%CVE-2026-39118HIGHAn issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client validation gap to invoke EPSS 0.1%CVE-2026-39197MEDIUMAn issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Service (DoS) via a crafEPSS 0.3%CVE-2026-39196CRITICALDatadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::paEPSS 0.3%CVE-2026-50887CRITICALA Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internaEPSS 0.3%CVE-2026-50891HIGHIncorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafteEPSS 0.3%CVE-2026-50890CRITICALBernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /stockreports/spendings.EPSS 0.3%CVE-2026-50875HIGHIncorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers to arbitrarily modiEPSS 0.3%CVE-2026-50889HIGHAn input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS) via sending a cEPSS 0.5%CVE-2026-50886CRITICALIncorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via aEPSS 0.3%CVE-2026-50884HIGHIncorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and access sensitive components.EPSS 0.3%CVE-2026-50876MEDIUMA cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payEPSS 0.2%CVE-2025-55649MEDIUMA NULL pointer dereference in the gf_media_map_esd function (media_tools/isom_tools.c) of GPAC MP4Box v2.4 allows attackers to cause a DeniaEPSS 0.2%CVE-2025-55647MEDIUMAn Out-of-Memory in the mp4_mux_cenc_insert_pssh function (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of SerEPSS 0.2%CVE-2025-55644MEDIUMA heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial EPSS 0.2%CVE-2026-39006CRITICALAn issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.EPSS 0.5%