Busca de CVEs
375.184 resultadosCVE-2026-37462HIGHAn integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (EPSS 0.3%CVE-2026-26378MEDIUMCross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in IEPSS 0.3%CVE-2026-46447MEDIUMOpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_infoEPSS 0.3%CVE-2026-39107MEDIUMA Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails to properly sanitizEPSS 0.3%CVE-2026-36615MEDIUMMercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 exposes an undocumented /agileconfigreset endpoint that returns internal buffer conEPSS 0.2%CVE-2026-36574HIGHA DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and execute arbitrary codEPSS 0.1%CVE-2026-36748CRITICALRockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.EPSS 0.3%CVE-2026-10692MEDIUMjohnhuang316 code-index-mcp search_code_advanced is_safe_regex_pattern redosEPSS 0.3%CVE-2026-10691MEDIUMwonderwhy-er DesktopCommanderMCP start_search search-manager.ts redosEPSS 0.4%CVE-2026-9732MEDIUMEmergencyWP <= 1.4.2 - Cross-Site Request Forgery to Plugin Settings UpdateEPSS 0.1%CVE-2026-7421MEDIUMPasseum Ticketing <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'shop_name' SettingEPSS 0.2%CVE-2026-10690MEDIUMwonderwhy-er DesktopCommanderMCP read_file filesystem.ts readFileFromUrl server-side request forgeryEPSS 0.2%CVE-2026-40108HIGHGLPI Vulnerable to Stored XSS in ITIL CostsEPSS 0.3%CVE-2026-41412MEDIUMalf.io vulnerable to Arbitrary File Read and Exfil via simpleHttpClient Extension ScriptEPSS 0.3%CVE-2026-35482HIGHalf.io has an Authenticated RCE via Extension Script Sandbox EscapeEPSS 0.2%CVE-2026-44654MEDIUMLibreChat: Shared-agent editor can globally delete owner's file records — breaks owner's other private agentsEPSS 0.3%CVE-2026-10688MEDIUMahujasid blender-mcp server.py execute_blender_code code injectionEPSS 0.2%CVE-2026-44653MEDIUMLibreChat Shared MCP Server View Leaks Decrypted Admin SecretsEPSS 0.3%CVE-2026-32625CRITICALLibreChat Exfiltrates Server Secrets via MCP Server URL InjectionEPSS 2.9%CVE-2026-10719LOWOpen Seachest/Seachest NVMe show Format Descriptors VulnerabilityEPSS 0.1%