Busca de CVEs

375.176 resultados
CVE-2026-11607HIGHTYPO3 CMS - Broken Access Control in Form FrameworkEPSS 0.2%CVE-2026-41031CRITICALA Stored Cross-Site Scripting (XSS) vulnerability occurs in Vinna Process MonitorEPSS 0.2%CVE-2026-52902MEDIUMAwxkit: path traversal via yaml !include directiveEPSS 0.1%CVE-2026-4058MEDIUMUser Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.2 - Missing Authorization to Authenticated (Subscriber+) Subscription Pack CancellationEPSS 0.2%CVE-2025-10263CRITICALArm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-EPSS 0.6%CVE-2026-10731CRITICALSQL injection in Nemon productsEPSS 0.3%CVE-2026-46749MEDIUMA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implemEPSS 0.1%CVE-2026-46748HIGHA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a binary that is configureEPSS 0.2%CVE-2026-46747MEDIUMA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not properly sanitize patEPSS 0.2%CVE-2026-46746HIGHA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly sanitize user input iEPSS 0.4%CVE-2026-24349HIGHA vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versioEPSS 0.1%CVE-2025-40808MEDIUMA vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CEPSS 0.2%CVE-2026-28262MEDIUMDell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A loEPSS 0.1%CVE-2026-6899MEDIUMImproper Check for Certificate Revocation in S2OPCEPSS 0.1%CVE-2026-8365HIGHBlocksy <= 2.1.41 - Authenticated (Contributor+) PHP Object Injection via Deserialization of Untrusted Data via 'blocksy_meta' REST API FieldEPSS 1.2%CVE-2026-8677MEDIUMPrime Elementor Addons <= 1.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget HTML Tag SettingsEPSS 0.2%CVE-2026-8599MEDIUMMailerPress <= 2.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via Campaign HTML Content FieldEPSS 0.2%CVE-2026-7542MEDIUMSlider Revolution 7.0 - 7.0.10 - Authenticated (Subscriber+) Sensitive Information DisclosureEPSS 0.3%CVE-2026-11616HIGHEvents Calendar for GeoDirectory <= 2.3.28 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.3%CVE-2026-49818MEDIUMApache Airflow Samba provider: Path traversal in GCSToSambaOperator via GCS object namesEPSS 0.7%