Busca de CVEs
375.176 resultadosCVE-2026-48107MEDIUMRussh: Unchecked keyboard-interactive prompt count in client auth pathEPSS 0.2%CVE-2026-10143HIGHkafka-python prior to 2.3.2 DoS via SCRAM Iteration Count in scram.pyEPSS 0.5%CVE-2026-42462HIGHFedify has an LD-Signature Bypass via JSON-LD Named-Graph RestructuringEPSS 0.2%CVE-2026-46705MEDIUMrussh server userauth state is not reset when authentication principal changesEPSS 0.2%CVE-2026-46702HIGHRussh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packetsEPSS 0.3%CVE-2026-46673HIGHRussh: Unchecked CryptoVec allocation and growth handling is reachable from local agent inputs in current russh releases and from remote SSH traffic in historical pre-0.58.0 releasesEPSS 0.3%CVE-2026-10142HIGHkafka-python prior to 2.3.2 Denial of Service via Protocol Parser Frame LengthEPSS 0.3%CVE-2026-46668LOWSpiceDB: Caveat structures with nested lists can result in improper cache reuseEPSS 0.3%CVE-2026-46669HIGH`openvm-pairing` pairing check missing proper subfield check on scaling factorEPSS 0.2%CVE-2022-48575LOWA person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state handling. This issueEPSS 0.2%CVE-2022-26758HIGHA malicious application may cause unexpected changes in memory shared between processes. A memory corruption issue was addressed with improvEPSS 0.1%CVE-2026-48011LOWShopware: Timing-attack on admin panel allowing enumeration of administrator usernamesEPSS 0.2%CVE-2026-46654HIGHPlonky3 MultiField32Challenger: transcript malleability and challenge entropy lossEPSS 0.1%CVE-2026-44692HIGHAuthenticated Sharp users can download unrelated Laravel Storage objects through the generic download endpointEPSS 0.3%CVE-2026-53634MEDIUMSharp: Missing Authorization Check in Quick Creation Command EndpointsEPSS 0.2%CVE-2026-45380LOWbit7z: Path Traversal via Null Byte Injection from `gcount()` Off-by-One in `restoreSymlink()`EPSS 0.1%CVE-2026-45384MEDIUMbit7z: Arbitrary File Overwrite via Symlink Attack on Predictable Temp File During Archive UpdateEPSS 0.1%CVE-2026-45106MEDIUMWeblate: Stored HTML injection in editor search previewEPSS 0.2%CVE-2026-50127MEDIUMWeblate SSRF: outbound URL guard misses the NAT64 well-known prefix (64:ff9b::/96)EPSS 0.3%CVE-2026-46683MEDIUMSnappy: SSRF and local file read via the xsl-style-sheet optionEPSS 0.2%