Busca de CVEs

375.176 resultados
CVE-2026-11411MEDIUMiAI Lab PDF AI App chatpdf.pro getExternalCacheDir path traversalEPSS 0.2%CVE-2026-11408MEDIUMvertex-app vertex Log Viewer Endpoint LogMod.js os command injectionEPSS 1.1%CVE-2026-11406MEDIUMGL.iNet MT3000 OpenVPN Client Import Workflow ovpnclient.sh command injectionEPSS 1.2%CVE-2026-10725HIGHProtocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2 BombEPSS 0.4%CVE-2026-9829MEDIUMPhoto Gallery by 10Web <= 1.8.41 - Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode ParameterEPSS 0.5%CVE-2026-9851HIGHBooking Package <= 1.7.16 - Authenticated (Editor+) Privilege Escalation via Account Takeover to updateUser AJAX ActionEPSS 0.4%CVE-2026-9016MEDIUMDebug Log Manager <= 2.5.0 - Unauthenticated Improper Output Neutralization for Logs via log_js_errors AJAX ActionEPSS 0.3%CVE-2026-9594MEDIUMWP Maps <= 4.9.4 - Authenticated (Admin+) Stored Cross-Site Scripting via 'location_messages' ParameterEPSS 0.3%CVE-2026-8611MEDIUMKlamra Paycal for Aspaclaria <= 1.1.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'invoice_id' ParameterEPSS 0.2%CVE-2026-8839MEDIUMMapPress Maps for WordPress <= 2.96.6 - Unauthenticated Insecure Direct Object Reference via REST API EndpointsEPSS 1.0%CVE-2026-7624MEDIUMSEO Plugin by Squirrly SEO <= 12.4.16 - Missing Authorization to Authenticated (Contributor+) Privileged Cloud API OperationsEPSS 0.3%CVE-2026-8978MEDIUMOptinCraft <= 1.2.0 - Authenticated (Administrator+) SQL Injection via 'order_by' ParameterEPSS 0.3%CVE-2026-7792MEDIUMWPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook EndpointEPSS 0.3%CVE-2026-2500MEDIUMQuick Playground <= 1.3.4 - Authenticated (Administrator+) Arbitrary File Read via 'filename' ParameterEPSS 0.3%CVE-2026-8502MEDIUMLearnPress <= 4.3.6 - Unauthenticated Sensitive Information Exposure via 'c_status' and 'return_type' ParametersEPSS 0.5%CVE-2026-7796MEDIUMEmbedPress <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block 'url' AttributeEPSS 0.3%CVE-2026-7665MEDIUMEssential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX HandlerEPSS 7.2%CVE-2026-7795MEDIUMClick to Chat <= 4.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'num' Shortcode ParameterEPSS 0.4%CVE-2026-7537HIGHMDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' ParameterEPSS 0.7%CVE-2026-7566MEDIUMLearnPress – Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object Injection via WXR XML File UploadEPSS 0.4%