Busca de CVEs

375.176 resultados
CVE-2026-45178HIGHIdira Secrets Manager Self-Hosted: Improper Access Control in Internal Cluster EndpointsEPSS 0.4%CVE-2026-53702MEDIUMGstreamer1-plugins-bad-free: gstreamer: stack buffer overflow in h.265 buffering period sei parserEPSS 0.2%CVE-2026-53701MEDIUMGstreamer1-plugins-bad-free: gstreamer: out-of-bounds write in h.266/vvc pps picture partition parserEPSS 0.2%CVE-2026-11774HIGH389-ds-base: 389-ds-base: integer overflow in sasl packet length bypasses size limit leading to heap buffer overflowEPSS 0.8%CVE-2026-48546HIGHKanaDojo < 0.1.18 Sandbox Escape RCE via messages.cjsEPSS 0.5%CVE-2026-47157MEDIUMaiograpi: Unsafe signup challenge path handlingEPSS 0.2%CVE-2026-46697HIGHFediverse Embeds: Unauthenticated SSRF / open proxy via REST media-proxy endpointEPSS 0.2%CVE-2026-46698MEDIUMFediverse Embeds: Public-nonce SSRF via ftf_get_site_info AJAX actionEPSS 0.2%CVE-2026-49261CRITICALMariaDB server has unsafe parameter handling in `wsrep_notify_cmd`EPSS 1.6%CVE-2026-3329HIGHNexus Repository Manager - Improper Restriction of Excessive Authentication AttemptsEPSS 0.4%CVE-2026-11986MEDIUMKeycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of keycloakEPSS 0.3%CVE-2026-11945MEDIUMPostgreSQL Anonymizer: SQL injection in the rules import functionsEPSS 0.2%CVE-2026-49982HIGHtmp: Type-confusion bypass of _assertPath in tmp@0.2.6 allows path traversal via non-string prefix/postfix/templateEPSS 0.5%CVE-2026-44705HIGHtmp: Path Traversal via unsanitized prefix/postfix enables directory escapeEPSS 0.4%CVE-2026-44486HIGHAxios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connectionEPSS 0.7%CVE-2026-44487HIGHAxios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP AdapterEPSS 0.7%CVE-2026-44488HIGHAxios: Allocation of Resources Without Limits or Throttling in axiosEPSS 0.6%CVE-2026-44490MEDIUMAxios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functionsEPSS 0.3%CVE-2026-44496HIGHAxios: Regular Expression Denial of Service (ReDoS) via Cookie Name InjectionEPSS 0.6%CVE-2026-44495HIGHAxios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config MergeEPSS 0.5%