Busca de CVEs

375.184 resultados
CVE-2026-46654HIGHPlonky3 MultiField32Challenger: transcript malleability and challenge entropy lossEPSS 0.1%CVE-2026-44692HIGHAuthenticated Sharp users can download unrelated Laravel Storage objects through the generic download endpointEPSS 0.3%CVE-2026-53634MEDIUMSharp: Missing Authorization Check in Quick Creation Command EndpointsEPSS 0.2%CVE-2026-45380LOWbit7z: Path Traversal via Null Byte Injection from `gcount()` Off-by-One in `restoreSymlink()`EPSS 0.1%CVE-2026-45384MEDIUMbit7z: Arbitrary File Overwrite via Symlink Attack on Predictable Temp File During Archive UpdateEPSS 0.1%CVE-2026-45106MEDIUMWeblate: Stored HTML injection in editor search previewEPSS 0.2%CVE-2026-50127MEDIUMWeblate SSRF: outbound URL guard misses the NAT64 well-known prefix (64:ff9b::/96)EPSS 0.3%CVE-2026-46683MEDIUMSnappy: SSRF and local file read via the xsl-style-sheet optionEPSS 0.2%CVE-2026-46643HIGHSnappy: Binary path is never shell-escaped due to an inverted is_executable checkEPSS 0.2%CVE-2026-6893HIGHDracut: dracut: root code execution via dhcp options command injectionEPSS 1.1%CVE-2026-46529HIGHPDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopenEPSS 0.5%CVE-2026-1220HIGHRace in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. EPSS 0.3%CVE-2026-11626MEDIUMLocal Privilege Escalation in Symantec Endpoint Protection macOS CleanWipe Removal ToolEPSS 0.1%CVE-2026-50639MEDIUMMetrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injectionsEPSS 0.3%CVE-2026-50638CRITICALMetrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injectionsEPSS 0.3%CVE-2026-50637HIGHMetrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injectionsEPSS 0.3%CVE-2026-10740MEDIUMExcessive memory allocation in s2n-quicEPSS 0.3%CVE-2026-46642MEDIUMdraw.io: XSS via crafted cell label when opening a .drawio fileEPSS 0.2%CVE-2026-11417HIGHOS Command Injection in NodejsFunction Bundling in aws-cdk-libEPSS 0.9%CVE-2026-45062HIGHFrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP FilesEPSS 0.6%