Busca de CVEs

375.176 resultados
CVE-2026-40519HIGHNginx Proxy Manager Authenticated RCE via setupCertbotPlugins()EPSS 0.9%CVE-2026-11583MEDIUMCodeAstro Student Attendance Management System createClass.php sql injectionEPSS 0.2%CVE-2026-49141MEDIUMWACRM Authorization Bypass via Automation Engine EndpointEPSS 0.2%CVE-2026-46484HIGHHeadplane: Path Traversal + RBAC Bypass in renameNode allows authenticated OIDC users to expire or rename any node/userEPSS 0.4%CVE-2026-47345MEDIUMTYPO3 HTML Sanitizer allows Cross-Site ScriptingEPSS 0.4%CVE-2026-47344LOWTYPO3 HTML Sanitizer allows Cross-Site ScriptingEPSS 0.3%CVE-2026-11582MEDIUMCodeAstro Student Attendance Management System index.php sql injectionEPSS 0.3%CVE-2026-11559MEDIUMCodeAstro Payroll System view_account.php sql injectionEPSS 0.2%CVE-2026-46490HIGHsamlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML AssertionsEPSS 0.5%CVE-2026-11393HIGHCode injection via improper triple-quote escaping in AgentCore CLI Bedrock Agent importEPSS 0.3%CVE-2026-46486MEDIUMMobile Verification Toolkit (MVT): Path Traversal via unsanitized File identifiers in iOS Backup processingEPSS 0.4%CVE-2026-11558MEDIUMCodeAstro Payroll System home_salary.php sql injectionEPSS 0.2%CVE-2026-10544MEDIUMImproper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authentEPSS 0.2%CVE-2026-10787MEDIUMMissing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadataEPSS 0.2%CVE-2026-10786MEDIUMImproper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain clEPSS 0.1%CVE-2026-52778CRITICALYesWiki has Unsafe eval() in Formula Calculator - Remote Code Execution (RCE) & Denial of Service (DoS)EPSS 0.6%CVE-2026-11557HIGHTenda F451 Web Management Natlimit fromNatlimit stack-based overflowEPSS 0.5%CVE-2026-11556HIGHTenda F451 Web Management WriteFacMac formWriteFacMac os command injectionEPSS 1.6%CVE-2026-11555MEDIUMD-Link DGS-1100-08PD Web boa.conf least privilege violationEPSS 0.4%CVE-2026-11554MEDIUMTOTOLINK CP450 vsftpd vsftpd.conf least privilege violationEPSS 0.2%