Busca de CVEs

375.184 resultados
CVE-2025-14772HIGHBroken Access Control in ABB T-MAC Plus web applicationEPSS 0.3%CVE-2025-14771HIGHFile Disclosure in ABB T-MAC Plus web application and in ABB T-MAC plus Server - Default IIS Web SiteEPSS 0.3%CVE-2025-15656HIGHWordPress School Management plugin <= 93.2.0 - Privilege Escalation vulnerabilityEPSS 0.2%CVE-2025-15655HIGHWordPress School Management plugin <= 93.2.0 - SQL Injection vulnerabilityEPSS 0.2%CVE-2025-15654HIGHWordPress Prague plugin <= 2.2.8 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.1%CVE-2026-4035HIGHEnvironment Variable Resolution Vulnerability in mlflow/mlflowEPSS 0.4%CVE-2026-5078MEDIUMmorgan vulnerable to Log Forging via unneutralized control characters in :remote-userEPSS 0.3%CVE-2026-50052LOWIn Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend requEPSS 0.4%CVE-2026-50031HIGHipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMEPSS 0.4%CVE-2026-10705LOWdask HLL hyperloglog.py nunique_approx resource consumptionEPSS 0.3%CVE-2026-10704MEDIUMSourceCodester Pizzafy E-Commerce System Administrative Control Panel admin_class_novo.php login sql injectionEPSS 0.3%CVE-2026-10703MEDIUMEIPStackGroup OpENer SendRRData cipmessagerouter.c CreateMessageRouterRequestStructure use after freeEPSS 0.2%CVE-2026-9516HIGHCpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throwsEPSS 0.4%CVE-2026-9334HIGHCpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabledEPSS 0.3%CVE-2026-10694MEDIUMSourceCodester Online Food Ordering System index.php include file inclusionEPSS 0.3%CVE-2026-10693MEDIUMSourceCodester Online Boat Reservation System Administrative Endpoint improper authorizationEPSS 0.2%CVE-2025-70101MEDIUMAn out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows attackers to cause a deEPSS 0.3%CVE-2026-26825MEDIUMA use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorEPSS 0.2%CVE-2026-26824MEDIUMlibxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory allocated for the MastEPSS 0.2%CVE-2026-36603HIGHMercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions without authentication on port 1900, incluEPSS 0.2%