Busca de CVEs
375.184 resultadosCVE-2026-20252HIGHServer-Side Request Forgery (SSRF) through Dashboard Studio PDF Export in Splunk EnterpriseEPSS 0.3%CVE-2026-20257MEDIUMImproper Input Validation through Classic Dashboard CSS in Splunk EnterpriseEPSS 0.3%CVE-2026-20259MEDIUMImproper Access Control in Splunk EnterpriseEPSS 0.2%CVE-2026-20255MEDIUMImproper Input Validation through Classic Dashboards in Splunk EnterpriseEPSS 0.4%CVE-2026-20251HIGHRemote Code Execution through Deserialization of Untrusted Data in Splunk Secure GatewayEPSS 19.0%CVE-2026-20254MEDIUMInformation Disclosure through External Content Restriction Bypass in Splunk EnterpriseEPSS 0.4%CVE-2026-20256MEDIUMImproper Input Validation through Protocol-Relative URL in Classic Dashboards in Splunk EnterpriseEPSS 0.4%CVE-2026-11596MEDIUMIn ScreenConnect™ versions prior to 26.2, input
validation within the Host Pass creation functionality could allow an
authenticated user witEPSS 0.2%CVE-2026-9151HIGHCommand Injection Vulnerability in OpenVPN on Multiple TP-Link Archer RoutersEPSS 1.1%CVE-2026-46609MEDIUMUmbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialogEPSS 0.1%CVE-2026-46616MEDIUMUmbraco.Cms: Open Redirect Vulnerability in Surface ControllersEPSS 0.2%CVE-2026-46497LOWSSRF via sitemap-derived URLs in Crawlee for PythonEPSS 0.3%CVE-2026-46558HIGHPlane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspacesEPSS 0.3%CVE-2026-45569HIGHRoxy-WI: Path-traversal patch in commit d4d10006 is a no-op (tuple-membership bug)EPSS 0.3%CVE-2026-45567HIGHRoxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /api/gptEPSS 0.2%CVE-2026-45566MEDIUMRoxy-WI: Open redirect on /login?next= via basic-auth userinfo syntax bypassEPSS 0.2%CVE-2026-45565HIGHRoxy-WI: EscapedString validator skips its '..' block when stripping (root cause for several path-traversal/RCE vectors)EPSS 0.3%CVE-2026-48096MEDIUMOpenFGA: Cache-key delimiter injection in openfga/openfga shared-iterator and v2 iterator caches enables intra-store authorization-decision poisoningEPSS 0.1%CVE-2026-53694HIGHPotential local privileges escalation through argument injection in the nxchmod.sh scriptEPSS 0.1%CVE-2026-25700HIGHApache Answer: AdminToken not invalidated after admin deactivationEPSS 0.4%