Busca de CVEs

375.176 resultados
CVE-2026-48907CRITICALJoomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5EPSS 55.9%KEVCVE-2026-21825MEDIUMHCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search centerEPSS 0.2%CVE-2026-21826MEDIUMHCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injectionEPSS 0.1%CVE-2026-21837HIGHHCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management APIEPSS 0.9%CVE-2026-10732MEDIUMAll versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archivEPSS 0.5%CVE-2026-50593HIGHGraphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that EPSS 0.1%CVE-2026-50592MEDIUMIn Znuny LTS before 6.5.21 and Znuny before 7.3.3, there is reflected XSS in AdminCommunicationLog (aka the communication log administratiEPSS 0.1%CVE-2026-50591MEDIUMIn Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can occur via stored user preferences.EPSS 0.1%CVE-2026-7763CRITICALHeap buffer overflow in morse.ko TIM IE processingEPSS 0.5%CVE-2026-7762CRITICALHeap buffer overflow in dot11ah.ko S1G Capabilities IE processingEPSS 0.6%CVE-2026-41567HIGHDocker: `PUT /containers/{id}/archive` executes container binary on the hostEPSS 0.2%CVE-2026-11312MEDIUMbytedance InfiniStore KV Map infinistore.h purge_kv_map algorithmic complexityEPSS 0.1%CVE-2026-50590MEDIUMIn Mimecast Incydr before 2.6.0, arbitrary file access can occur.EPSS 0.1%CVE-2026-11326MEDIUMOpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site scripting vulnerabiliEPSS 0.2%CVE-2026-10878MEDIUMD-Link DWR-M920 formSmsManage sub_41C8E8 command injectionEPSS 4.2%CVE-2026-36785HIGHShenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the page parameter of the fromDhcpListEPSS 0.4%CVE-2026-37737MEDIUMsanic-cors version 2.2.0 and prior contains an improper regular expression in the try_match() function in sanic_cors/core.py that uses re.maEPSS 0.2%CVE-2026-36500CRITICALAn issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a craftEPSS 0.7%CVE-2026-38579MEDIUMMultiple reflected Cross-Site Scripting (XSS) vulnerabilities in damasac thaipalliative_lte through version 3.0 allow remote attackers to inEPSS 0.2%CVE-2026-36501HIGHAn issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to cause a Denial of Service (DoS) via a crafEPSS 0.3%