Busca de CVEs

375.176 resultados
CVE-2026-0416MEDIUMImproper input validation in certain NETGEAR routers allows unauthorized modification of protected router functionalityEPSS 0.2%CVE-2026-3088MEDIUMUnauthenticated users can disrupt router operationEPSS 0.4%CVE-2026-9213MEDIUMInsufficient input validation in certain NETGEAR routersEPSS 0.4%CVE-2026-0419MEDIUMInsufficient input validation vulnerability in NETGEAR JR6150EPSS 0.3%CVE-2026-0412MEDIUMInsufficient input validation vulnerability in NETGEAR JR6150 Web UIEPSS 0.2%CVE-2026-0410LOWInsufficient input validation in certain NETGEAR routersEPSS 0.2%CVE-2026-28301MEDIUMSolarWinds Observability Self-Hosted Open Redirect VulnerabilityEPSS 0.2%CVE-2026-0409MEDIUMNetgear Orbi 370 Series Remote Code Execution vulnerabilityEPSS 0.3%CVE-2026-49948HIGHMem0 0.2.8 Missing Authorization via POST /configure EndpointEPSS 0.3%CVE-2026-24065HIGHLocal Privilege Escalation via Insecure XPC Client Validation in Waves Central for macOSEPSS 0.3%CVE-2026-24064HIGHLocal Privilege Escalation via Dynamic Library Injection in Waves Central for macOSEPSS 0.2%CVE-2026-8045HIGHCWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side fiEPSS 0.2%CVE-2026-8025CRITICALSQLi in MOSK Informatics' CBS PlatformEPSS 0.3%CVE-2026-10727HIGHAn OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker EPSS 13.6%CVE-2025-67862MEDIUMAn Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6EPSS 0.1%CVE-2026-25089CRITICALA improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 thEPSS 73.6%KEVCVE-2026-49938MEDIUMA improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all veEPSS 0.2%CVE-2026-10523CRITICALAn Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthentEPSS 51.9%CVE-2026-10520CRITICALAn OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated userEPSS 99.9%CVE-2026-49762MEDIUMUnbounded integer parsing in the Version module enables CPU and memory exhaustion denial of serviceEPSS 0.2%