Búsqueda de CVEs

369.364 resultados
CVE-2026-14404MEDIUMInappropriate implementation in PDFium in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafteEPSS 0.2%CVE-2026-14427HIGHHeap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to pEPSS 0.2%CVE-2026-14385HIGHHeap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform out of bounds memory accesEPSS 0.3%CVE-2026-50283MEDIUMCraft CMS: Unauthorized Deletion of Source Assets During File ReplacementEPSS 0.3%CVE-2026-55793MEDIUMCraft CMS: Stored XSS via Structure entry title in table viewEPSS 0.4%CVE-2026-54712MEDIUMOpenTelemetry Javaagent RMI context propagation allows resource exhaustionEPSS 0.3%CVE-2026-54704MEDIUMOpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text PasswordsEPSS 0.2%CVE-2026-54263HIGHWagtail: Reflected XSS in dynamic image URL generator viewEPSS 0.2%CVE-2026-54262MEDIUMWagtail: Pages translations can be created without page permissions when using simple_translationEPSS 0.2%CVE-2026-54261MEDIUMWagtail: Improper permission handling in image previewEPSS 0.2%CVE-2026-54259MEDIUMWagtail: Improper restriction handling on Documents and Images chosen endpointsEPSS 0.2%CVE-2026-54260MEDIUMWagtail: Denial of service via unbounded filter specs in the image previewEPSS 0.2%CVE-2026-14340MEDIUMAn incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositoriesEPSS 0.2%CVE-2026-54720MEDIUMSilverstripe Framework: Possible XSS attack through media embedEPSS 0.3%CVE-2026-55660HIGHTinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeoverEPSS 0.2%CVE-2026-54074HIGH@tinacms/cli: Remote Code Execution via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labelsEPSS 0.2%CVE-2026-55661MEDIUMTinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemesEPSS 0.2%CVE-2026-58263HIGHJodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrierEPSS 0.2%CVE-2026-54756MEDIUMJodit Editor: Prototype pollution via Jodit.configure() / ConfigMergeEPSS 0.3%CVE-2026-55886MEDIUMJodit Editor: Prototype Pollution in Jodit via Jodit.modules.Helpers.set()EPSS 0.3%