Busca de CVEs
375.176 resultadosCVE-2026-12189MEDIUMMoovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url schemeEPSS 0.1%CVE-2026-12188MEDIUMGrit42 Grit GritEntityController grit_entity_controller.rb sql injectionEPSS 0.2%CVE-2026-12187HIGHGL.iNet GL-MT3000 Online Firmware Upgrade one_click_upgrade command injectionEPSS 1.9%CVE-2026-12186HIGHGL.iNet GL-MT3000 Tor Proxy Service Configuration tor replace_country command injectionEPSS 2.0%CVE-2026-54413HIGHiso14229 Integer Underflow and Out-of-Bounds Read in Handle_0x27_SecurityAccess()EPSS 0.5%CVE-2026-54412HIGHMQTT-C Heap Out-of-Bounds Read and Integer Underflow in mqtt_unpack_publish_response()EPSS 0.4%CVE-2026-54411MEDIUMLinux-PAM pam_userdb Observable Timing Discrepancy in Plaintext Password ComparisonEPSS 0.3%CVE-2026-54410HIGHnanoMODBUS Off-by-One Buffer Overflow in recv_msg_header() via Crafted MBAP Length FieldEPSS 0.5%CVE-2026-11527HIGHConfig::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandleEPSS 1.1%CVE-2026-11526CRITICALGD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandleEPSS 1.4%CVE-2025-15546MEDIUMIptanus File Upload < 5.1.7 - File Overwrite via Race ConditionEPSS 0.2%CVE-2026-54421MEDIUMIn OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can returnEPSS 0.3%CVE-2026-54420HIGHLiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTPEPSS 1.4%KEVCVE-2026-12176MEDIUMSourceCodester CET Automated Grading System with AI Predictive Analytics index.php cross site scriptingEPSS 0.3%CVE-2026-12175MEDIUMCodeAstro Student Attendance Management System createStudents.php sql injectionEPSS 0.2%CVE-2026-12174HIGHD-Link DCS-935L HTTP rhea snprintf format stringEPSS 0.6%CVE-2026-12183CRITICALNefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary CredentialsEPSS 0.5%CVE-2026-6428MEDIUMKoha SQL Injection in reports/catalogue_out.pl via Filter URL ParameterEPSS 0.2%CVE-2026-5513HIGHOnline Scheduling and Appointment Booking System – Bookly <= 27.2 - Unauthenticated Stored Cross-Site Scripting via 'bookly-customer-full-name' CookieEPSS 0.4%CVE-2026-11624CRITICALThe Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNEPSS 0.2%