Busca de CVEs
375.176 resultadosCVE-2026-53606MEDIUMsanitize-html has an incomplete URI scheme validation that allows javascript: URIs through action, formaction, data, poster, and background attributesEPSS 0.1%CVE-2026-45014MEDIUMApostrophe Vulnerable to Stored Cross-Site Scripting via Unsanitized User Display Name in Draft Version TooltipEPSS 0.3%CVE-2026-54396MEDIUMMISP AuthKey edit endpoint allows authenticated user email enumerationEPSS 0.2%CVE-2026-45013HIGHApostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input ValidationEPSS 0.3%CVE-2026-24618MEDIUMWordPress Hash Elements plugin <= 1.5.4 - Sensitive Data Exposure vulnerabilityEPSS 0.2%CVE-2026-12130MEDIUMCodeAstro Human Resource Management System Projects Management Add_Projects cross site scriptingEPSS 0.2%CVE-2026-45012HIGHApostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widgetEPSS 0.2%CVE-2026-45011HIGHApostrophe has stored XSS via javascript: URL in Image Widget LinkEPSS 0.2%CVE-2026-44990CRITICALApostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`EPSS 0.5%CVE-2026-42853MEDIUM@apostrophecms/cli: Command Injection in apos create via Unsanitized Password InputEPSS 0.4%CVE-2026-54395MEDIUMMISP UiBeta event index reflected XSS in advanced filter popupEPSS 0.3%CVE-2026-54394MEDIUMMISP organisation logo path traversal allows retrieval of arbitrary PNG/SVG filesEPSS 0.3%CVE-2026-12129MEDIUMCodeAstro Human Resource Management System Dashboard add_tod cross site scriptingEPSS 0.2%CVE-2026-47264MEDIUMDiscourse: Don't leak restricted tag group names via tag infoEPSS 0.2%CVE-2026-47263MEDIUMDiscourse: Prevent webhook payload disclosure on event redeliveryEPSS 0.2%CVE-2026-45775MEDIUMDiscourse: Cross-site backup access via path traversal in multisite local backupsEPSS 0.3%CVE-2026-45085MEDIUMDiscourse: Chat misauthorization and information disclosureEPSS 0.2%CVE-2026-44785MEDIUMDiscourse: Hidden reply-to post raw can be disclosed through AI explain promptsEPSS 0.2%CVE-2026-44784MEDIUMDiscourse: Non-staff group owners can see email password in plaintext through group historyEPSS 0.2%CVE-2026-44783MEDIUMDiscourse: Replying to a whisper lets non-whisperers create staff-only whisper postsEPSS 0.1%