Busca de CVEs

375.176 resultados
CVE-2026-40997MEDIUMSOAP security faults leak Spring Security account stateEPSS 0.4%CVE-2026-40996MEDIUMInbound WS-Security allows RSA PKCS#1 v1.5 key transport by defaultEPSS 0.1%CVE-2026-40995MEDIUMX.509 authentication bypasses Spring Security account checksEPSS 0.1%CVE-2026-40994HIGHWss4jSecurityInterceptor disables WS-I BSP validation by defaultEPSS 0.2%CVE-2026-40992MEDIUMMail Auto-Configuration Does Not Enable SSL Hostname VerificationEPSS 0.1%CVE-2026-40987HIGHRemote-file synchronizer in Spring Integration writes server-supplied filename under localDirectory without canonicalizationEPSS 0.2%CVE-2026-40986MEDIUMSpring Web Flow JS RemotingHandler renders non-HTML Response as HTMLEPSS 0.2%CVE-2026-40985MEDIUMData Binding Vulnerability in Spring Web Flow with Unified EL ParserEPSS 0.2%CVE-2026-35273CRITICALVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported vEPSS 95.5%KEVCVE-2026-2827MEDIUMOpen User Map PRO <= 1.4.31 - Unauthenticated Stored Cross-Site Scripting via 'oum_location_notification'EPSS 0.2%CVE-2026-38581CRITICALSQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via EPSS 0.3%CVE-2026-47342HIGHApache OFBiz: Privilege Escalation via updateOrRemove Authorization BypassEPSS 0.4%CVE-2026-46645MEDIUMSQLAdmin: Authorization Bypass on `ajax_lookup`EPSS 0.3%CVE-2026-50223HIGHApache OFBiz: DataResource Low-Privileged Authenticated FreeMarker Template Injection Leads to Remote Code ExecutionEPSS 0.7%CVE-2026-46695CRITICALBoxLite: Permission Bypass in boxlite Allows Modification of Read-Only FilesEPSS 0.3%CVE-2026-46703CRITICALBoxLite: Path Traversal Vulnerability in boxlite Leads to Arbitrary File Write on the HostEPSS 0.5%CVE-2026-47213MEDIUMBoxLite: Timeout Bypass VulnerabilityEPSS 0.3%CVE-2026-42568MEDIUMYamcs Vulnerable to LDAP Injection in LdapAuthModuleEPSS 1.0%CVE-2026-52726HIGHDulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped .git/hooks payloadEPSS 0.4%CVE-2026-44693HIGHPi-hole FTL: Unauthenticated Session Hijacking via Race Condition on Global Session BufferEPSS 0.3%