Busca de CVEs
375.184 resultadosCVE-2026-10805MEDIUMNetworkmanager: networkmanager: local privilege escalation via malformed mud urls in dhclient backendEPSS 0.2%CVE-2026-50219MEDIUMlibexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParseEPSS 0.3%CVE-2026-49188HIGHElevated Root Command Execution via ai_cmd SocketsEPSS 0.3%CVE-2026-49187HIGHHard-coded APK Resource Credentials & SceptersEPSS 0.2%CVE-2026-49186HIGHLack of MQTT Broker Topic Access Control ListsEPSS 0.3%CVE-2026-49185CRITICALInstruction Injection via FieldX MDMEPSS 0.4%CVE-2026-41010HIGHReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where EPSS 0.1%CVE-2026-41011HIGHPackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_EPSS 0.1%CVE-2026-10597MEDIUMITPison|OMICARD EDM - Insecure Direct Object ReferenceEPSS 0.2%CVE-2026-41858MEDIUMWeak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities-release allows a neEPSS 0.2%CVE-2026-8829HIGHHTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entitiesEPSS 0.4%CVE-2026-41859HIGHA network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secrEPSS 0.1%CVE-2026-41860HIGHCWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_asEPSS 0.1%CVE-2026-8653MEDIUMMasterStudy LMS Pro Plus <= 4.8.20 - Authenticated (Instructor+) SQL Injection via 'columns' ParameterEPSS 0.2%CVE-2026-10737HIGHSP Project & Document Manager <= 4.71 - Missing Authorization to Unauthenticated Arbitrary File Information Disclosure via view_file() FunctionEPSS 0.4%CVE-2026-7764MEDIUMOut-of-bounds read in morse.ko Vendor IE processingEPSS 0.1%CVE-2026-48681MEDIUMOpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.EPSS 0.6%CVE-2026-38570HIGHbacnet_stack 1.3.1 contains an Out-of-bounds Read in bacnet_tag_number_decode which allows attackers to cause a denial of service.EPSS 0.3%CVE-2026-36176HIGHGNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows EPSS 0.1%CVE-2026-41283CRITICALOpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code executiEPSS 0.7%