Busca de CVEs
375.176 resultadosCVE-2026-8335HIGHMissing authentication in Aix-DBEPSS 0.2%CVE-2025-10238HIGHDuring an internal security assessment, a potential out-of-bounds write vulnerability was discovered in the BIOS of some ThinkPad products cEPSS 0.1%CVE-2025-10237HIGHDuring an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could alEPSS 0.1%CVE-2026-6090HIGHA potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticated user to execute arEPSS 0.1%CVE-2026-8637HIGHA potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could allow a local authentEPSS 0.1%CVE-2026-9045HIGHDuring an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise foEPSS 0.1%CVE-2026-7516MEDIUMA vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese market, that could allowEPSS 0.2%CVE-2026-11884MEDIUM389-ds-base: 389-ds-base: heap buffer overflow in schema objectclass serialization due to missing oc_superior in size calculationEPSS 0.3%CVE-2026-45564HIGHRoxy-WI: Authenticated RCE via 'configver' URL parameter (os.system sink in /config/versions/.../save)EPSS 0.3%CVE-2026-45563MEDIUMRoxy-WI: IDOR — any authenticated user can read another user's full action historyEPSS 0.2%CVE-2026-45561MEDIUMRoxy-WI: SSRF in /smon/agent/<endpoint>/<server_ip> reachable to cloud metadata IPsEPSS 0.2%CVE-2026-45560MEDIUMRoxy-WI: Stored XSS in log viewer (wrap_line/highlight_word produce unescaped HTML)EPSS 0.1%CVE-2026-45559MEDIUMRoxy-WI: LDAP injection in /user/ldap/<username> (admin-only)EPSS 0.2%CVE-2026-45558CRITICALRoxy-WI: Authenticated RCE on every managed HAProxy load balancer via `option` field config injection in section saveEPSS 0.4%CVE-2026-45556CRITICALRoxy-WI: Authenticated arbitrary file write on every managed load balancer (and downstream RCE) via WAF rule save `config_file_name`EPSS 0.4%CVE-2026-45550CRITICALRoxy-WI: IDOR on PUT /smon/check — any user can rewrite any tenant's monitoring URL/IP/bodyEPSS 0.2%CVE-2026-45549HIGHRoxy-WI: Authorization bypass on POST /smon/agent/action/<action> — guest can stop or restart smon-agent on any hostEPSS 0.2%CVE-2026-45552CRITICALRoxy-WI: Cross-tenant authorization bypass on /install/* — guest can run Ansible / SSH on every registered serverEPSS 0.3%CVE-2026-53470CRITICALMigration-planner: getsourcedownloadurl missing organization checkEPSS 0.3%CVE-2026-53476CRITICALAssisted-migration-agent: vddk tarball chained-symlink arbitrary file writeEPSS 0.3%