Busca de CVEs
375.176 resultadosCVE-2026-50545CRITICALFission Environment CRD PodSpec Injection Leading to Node Escape and Cluster TakeoverEPSS 0.3%CVE-2026-49824HIGHFission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhookEPSS 0.2%CVE-2026-49823HIGHFission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhookEPSS 0.3%CVE-2026-49822HIGHFission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillanceEPSS 0.2%CVE-2026-49821HIGHFission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltrationEPSS 0.2%CVE-2026-46618MEDIUMFission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executablesEPSS 0.4%CVE-2026-46617HIGHFission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap readEPSS 0.3%CVE-2026-46612HIGHFission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archivesEPSS 0.3%CVE-2026-46614CRITICALFission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTriggerEPSS 0.4%CVE-2026-20258HIGHStored Cross-Site Scripting (XSS) through Classic Dashboard in Splunk EnterpriseEPSS 0.2%CVE-2026-20253CRITICALUnauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk EnterpriseEPSS 96.9%KEVCVE-2026-20260MEDIUMLog Injection through HTTP Request Paths in Splunk SOAREPSS 0.2%CVE-2026-20252HIGHServer-Side Request Forgery (SSRF) through Dashboard Studio PDF Export in Splunk EnterpriseEPSS 0.3%CVE-2026-20257MEDIUMImproper Input Validation through Classic Dashboard CSS in Splunk EnterpriseEPSS 0.3%CVE-2026-20259MEDIUMImproper Access Control in Splunk EnterpriseEPSS 0.2%CVE-2026-20255MEDIUMImproper Input Validation through Classic Dashboards in Splunk EnterpriseEPSS 0.4%CVE-2026-20251HIGHRemote Code Execution through Deserialization of Untrusted Data in Splunk Secure GatewayEPSS 19.0%CVE-2026-20254MEDIUMInformation Disclosure through External Content Restriction Bypass in Splunk EnterpriseEPSS 0.4%CVE-2026-20256MEDIUMImproper Input Validation through Protocol-Relative URL in Classic Dashboards in Splunk EnterpriseEPSS 0.4%CVE-2026-11596MEDIUMIn ScreenConnect™ versions prior to 26.2, input
validation within the Host Pass creation functionality could allow an
authenticated user witEPSS 0.2%