Busca de CVEs
375.176 resultadosCVE-2026-7047MEDIUMFrontend User Notes <= 2.1.1 - Cross-Site Request Forgery to Note Content Modification via 'confirmEdit' ActionEPSS 0.1%CVE-2026-8900MEDIUMSimple SEO Slideshow <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode AttributesEPSS 0.2%CVE-2025-12656LOWMigration, Backup, Staging – WPvivid Backup & Migration <= 0.9.128 - Authenticated (Admin+) Arbitrary Directory DeletionEPSS 0.4%CVE-2026-8893MEDIUMExpress Payment For Stripe <= 1.28.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode AttributesEPSS 0.2%CVE-2026-7523MEDIUMAlba Board <= 2.1.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'card_id' ParameterEPSS 0.3%CVE-2026-7654HIGHAdmin Columns <= 7.0.18 - Authenticated (Contributor+) PHP Object Injection to Remote Code Execution via Custom Field Meta ValueEPSS 0.9%CVE-2026-45409MEDIUMInternationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fixEPSS 0.4%CVE-2026-11416HIGHMoviePilot Path Traversal via Cloud Storage Download HandlersEPSS 0.5%CVE-2026-11431HIGHPath Traversal in Altium Projects Service Allows Arbitrary File ReadEPSS 0.5%CVE-2026-11429CRITICALPath Traversal in Altium Vault ScriptsController Allows Unauthenticated Remote Code ExecutionEPSS 1.1%CVE-2026-11424HIGHServer-Side Request Forgery in Altium Platform Design GraphQL Service Allows Information DisclosureEPSS 0.2%CVE-2026-11422HIGHMarkdown Preview Enhanced 0.8.x Code Injection via WaveDrom RenderingEPSS 0.2%CVE-2026-11423CRITICALPath Traversal in Altium Enterprise Server Collaboration Service Allows Privilege EscalationEPSS 0.3%CVE-2026-11420CRITICALPath Traversal in Altium Enterprise Server NIS Allows Unauthenticated Arbitrary File Write and File ReadEPSS 0.7%CVE-2026-11419CRITICALPath Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File WriteEPSS 0.5%CVE-2026-45758CRITICALMalicious code in guardrails-ai 0.10.1 (supply chain compromise)EPSS 0.3%CVE-2026-25624MEDIUMArista Edge Threat Management NGFW UI Administrative Cross-Site ScriptingEPSS 0.2%CVE-2026-45300HIGHasync-http-client: Cookie header not stripped on cross-origin redirectEPSS 0.3%CVE-2026-25623HIGHArista Edge Threat Management NGFW UI Arbitrary Command ExecutionEPSS 6.0%CVE-2026-45779CRITICALOpen XDMoD Vulnerable to Unauthenticated SQL Injection Leading to Full Database CompromiseEPSS 0.5%