Vulnerabilidades em CISA
27 resultadosAnálise Vexday
A CISA apresenta um perfil de risco baixo com 12 CVEs catalogadas, nenhuma atualmente sob exploração ativa e apenas 2 classificadas como críticas. A fraqueza dominante é buffer overflow (CWE-787), padrão em software legado, mas a vulnerabilidade mais recente data de mais de 90 dias, indicando risco estável e sem pressão imediata de remediação.
CVE-2026-90454MEDIUMA deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routEPSS 0.2%CVE-2026-90446MEDIUMAn application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request EPSS 0.2%CVE-2026-90448HIGHA deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restrEPSS 0.2%CVE-2025-35434LOWCISA Thorium does not validate TLS connections to ElasticsearchEPSS 0.2%CVE-2025-67634MEDIUMSoftware Acquisition Guide Supplier Response Web Tool XSSEPSS 0.2%CVE-2026-90457MEDIUMThe administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, aEPSS 0.1%CVE-2026-90452MEDIUMRequests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify tEPSS 0.1%