Busca de CVEs

375.176 resultados
CVE-2026-45169HIGHIdira Privileged Access Manager (PAM) Self-Hosted Vault: Denial of Service due to Unexpected Input ProcessingEPSS 0.4%CVE-2026-47370CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain deEPSS 0.8%CVE-2026-47369CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain deEPSS 0.3%CVE-2026-48613HIGHSQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field data during migration, EPSS 0.2%CVE-2026-47368HIGHA malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtaiEPSS 0.4%CVE-2026-48612HIGHImproper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s aEPSS 0.1%CVE-2026-47367CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID EnterpEPSS 0.8%CVE-2026-48610HIGHUnder certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found EPSS 0.3%CVE-2026-47366HIGHImproper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticatEPSS 0.3%CVE-2026-47365CRITICALArgument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass croEPSS 0.4%CVE-2026-48611CRITICALImproper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to uEPSS 3.9%CVE-2026-20746MEDIUMPingDirectory copying of virtual attributes leads to memory exhaustionEPSS 0.3%CVE-2026-11933HIGHPost-authentication use-after-free in server-side JavaScript BSON-to-array conversionEPSS 0.4%CVE-2026-9125MEDIUMThe Ultimate Video Player For WordPress <= 4.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'link_url' Shortcode AttributeEPSS 0.4%CVE-2026-45170HIGHIdira Vendor PAM - Self-Hosted Connector: Potential Security Bypass due to Incomplete TLS Certificate ValidationEPSS 0.1%CVE-2026-49482MEDIUMClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle OverwriteEPSS 0.2%CVE-2026-47238MEDIUMClipBucket: IDOR in videos subtitle editorEPSS 0.2%CVE-2026-45060CRITICALClipBucket: Blind SQL Injection in progress_video.phpEPSS 0.4%CVE-2026-42846CRITICALClipBucket: Remote Play URL Command InjectionEPSS 0.6%CVE-2026-45418HIGHClipBucket: Blind SQL Injection in subtitle_edit.phpEPSS 0.3%