Busca de CVEs
375.176 resultadosCVE-2026-50287HIGHMissing Authentication for Critical Function in @agenticmail/mcpEPSS 0.4%CVE-2026-42604MEDIUMActual has an OpenID `client_secret` Disclosure via Broken Authorization Guard in `/openid/config`EPSS 0.4%CVE-2026-53726MEDIUMParse Server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACLEPSS 0.3%CVE-2026-12043HIGHHeap double-free in AWS Common Runtime aws-c-httpEPSS 0.4%CVE-2026-53725MEDIUMParse Server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is deniedEPSS 0.3%CVE-2026-53724LOWParse Server: Stored XSS via trailing-dot filename bypassing file upload extension blocklistEPSS 0.3%CVE-2026-50099MEDIUMNaxclow IoT Platform Insertion of sensitive information into Externally-Accessible file or directoryEPSS 0.2%CVE-2026-50008MEDIUMParse Server: Server option routeAllowList is bypassable through batch sub-requestsEPSS 0.3%CVE-2026-10715MEDIUMCamaleon CMS 2.9.2 - Improper authorization in draft autosave endpointEPSS 0.2%CVE-2026-47138HIGHParse Server: Pre-authentication denial of service via client version header regex backtrackingEPSS 0.6%CVE-2026-47248MEDIUMParse Server: GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callersEPSS 0.3%CVE-2026-50244MEDIUMNaxclow IoT Platform Missing AuthorizationEPSS 0.2%CVE-2026-42932MEDIUMNaxclow IoT Platform Generation of Predictable Numbers or IdentifiersEPSS 0.2%CVE-2026-42947HIGHNaxclow IoT Platform Authorization bypass through User-Controlled keyEPSS 0.3%CVE-2026-47236MEDIUMSolidtime team page exposes pending invitation and member emails to employees who lack invitations:view/members:view permissionEPSS 0.2%CVE-2026-50108HIGHNaxclow IoT Platform Missing AuthorizationEPSS 0.3%CVE-2026-42306HIGHMoby: Race condition in docker cp allows bind mount redirection to host pathEPSS 0.1%CVE-2026-41568MEDIUMMoby: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swapEPSS 0.1%CVE-2026-50101CRITICALNaxclow IoT Platform Not using password agingEPSS 0.3%CVE-2026-28742CRITICALNaxclow IoT Platform Use of hard-coded cryptographic keyEPSS 0.3%