Busca de CVEs
375.165 resultadosCVE-2025-30238HIGHPrivilege Escalation via Improper Authorization in User Management in multiple TP-Link Aginet DevicesEPSS —CVE-2025-30237HIGHAuthentication Bypass via Broken Access Control in Web Server in Multiple TP-Link Aginet DevicesEPSS —CVE-2025-32736MEDIUMPingFederate Administrative Console CSRF weaknessesEPSS —CVE-2026-72919MEDIUMRocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthorized Conversion of Public Channels into TeamsEPSS —CVE-2026-72918MEDIUMRocket.Chat: Insecure implementation of websocket notificationsEPSS —CVE-2026-72917MEDIUMAnythingLLM: Password recovery accepts one recovery code twice after whitespace normalizationEPSS —CVE-2026-6426MEDIUMQemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds accessEPSS —CVE-2026-72916MEDIUMMastodon: SSRF Protection Bypass via IPv4-compatible IPv6 AddressesEPSS —CVE-2026-72915HIGHMastodon: Personally-identifying information disclosure due to incorrect access control validationEPSS —CVE-2026-72914HIGHMastodon: Exhausting data by an unauthenticated request to the admin retention APIEPSS —CVE-2026-48160CRITICALreact-tracked was vulnerable to malicious code execution via compromised commitsEPSS —CVE-2026-72913HIGHKitty: Command injection into the child shell via chained @kitty-echo + @kitty-ssh DCS escape sequencesEPSS —CVE-2026-72912MEDIUMCyberChef’s pretty-recipe parser vulnerable to client-side ReDoS / CPU exhaustion when parsing a malformed #recipe= URLEPSS —CVE-2026-72911CRITICALERPNext: Possibility of server-side template injection due to missing validationEPSS —CVE-2026-72910HIGHERPNext: Unauthorised modification of master data due to missing validationEPSS —CVE-2026-72909HIGHERPNext: Broken Access Control on certain endpointsEPSS —CVE-2026-72908MEDIUMERPNext: Possibility of SQL injection due to missing validationEPSS —CVE-2026-72907MEDIUMERPNext: Broken Access Control on certain endpointEPSS —CVE-2026-72906MEDIUMERPNext: Unauthorised triggering of automated emails due to missing validationEPSS —CVE-2026-19411LOWShim/dp.c library: null-pointer dereference in is_removable_media_path() when devicepathtostr() returns nullEPSS —