Busca de CVEs
375.176 resultadosCVE-2026-44976MEDIUMFrappe: IDOR in update_onboarding_stepEPSS 0.3%CVE-2026-48006HIGHNetty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregatorEPSS 0.6%CVE-2026-44975MEDIUMFrappe: Missing authorization on reset form toursEPSS 0.3%CVE-2026-44206MEDIUMFrappe: DB Schema Enumeration via Frappe-Authorization-SourceEPSS 0.3%CVE-2026-47691HIGHNetty has Insufficient Bailiwick Validation for NS RecordsEPSS 0.3%CVE-2026-40677HIGHThe use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle attack, potentially leadEPSS 0.4%CVE-2026-44207MEDIUMFrappe: Insecure Direct Object Reference for email accountsEPSS 0.3%CVE-2026-5792MEDIUMAuthentication Bypass in Hedef Media's Related Marketing Cloud (RMC)EPSS 0.2%CVE-2026-44208MEDIUMFrappe: IDOR in `submit_discussion()`EPSS 0.3%CVE-2026-47244MEDIUMNetty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforcedEPSS 0.3%CVE-2026-44205MEDIUMFrappe: Stored Cross-Site Scripting (XSS) in User Profile through Image UploadEPSS 0.3%CVE-2026-41581MEDIUMFrappe Vulnerable to Possible SQL Injection via get_blog_listEPSS 0.2%CVE-2026-47739MEDIUMFrappe: Stored XSS in NoteEPSS 0.3%CVE-2026-46340HIGHNetty: SCTP reassembly nests buffers without boundEPSS 0.4%CVE-2026-45674HIGHNetty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME RecordsEPSS 0.2%CVE-2026-47141MEDIUMvm2: NodeVM observability builtins leak host process and HTTP request dataEPSS 0.3%CVE-2026-47210CRITICALvm2 sandbox escape via JSPI-backed Promise `.finally()` species bypassEPSS 1.8%CVE-2026-47208CRITICALvm2: Sandbox Breakout Using Promise SpeciesEPSS 0.8%CVE-2026-47140CRITICALvm2: NodeVM builtin denylist bypass via process and inspector/promises allows host code executionEPSS 0.8%CVE-2026-45673MEDIUMNetty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source PortEPSS 0.3%