Busca de CVEs

375.165 resultados
CVE-2025-30238HIGHPrivilege Escalation via Improper Authorization in User Management in multiple TP-Link Aginet DevicesEPSS CVE-2025-30237HIGHAuthentication Bypass via Broken Access Control in Web Server in Multiple TP-Link Aginet DevicesEPSS CVE-2025-32736MEDIUMPingFederate Administrative Console CSRF weaknessesEPSS CVE-2026-72919MEDIUMRocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthorized Conversion of Public Channels into TeamsEPSS CVE-2026-72918MEDIUMRocket.Chat: Insecure implementation of websocket notificationsEPSS CVE-2026-72917MEDIUMAnythingLLM: Password recovery accepts one recovery code twice after whitespace normalizationEPSS CVE-2026-6426MEDIUMQemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds accessEPSS CVE-2026-72916MEDIUMMastodon: SSRF Protection Bypass via IPv4-compatible IPv6 AddressesEPSS CVE-2026-72915HIGHMastodon: Personally-identifying information disclosure due to incorrect access control validationEPSS CVE-2026-72914HIGHMastodon: Exhausting data by an unauthenticated request to the admin retention APIEPSS CVE-2026-48160CRITICALreact-tracked was vulnerable to malicious code execution via compromised commitsEPSS CVE-2026-72913HIGHKitty: Command injection into the child shell via chained @kitty-echo + @kitty-ssh DCS escape sequencesEPSS CVE-2026-72912MEDIUMCyberChef’s pretty-recipe parser vulnerable to client-side ReDoS / CPU exhaustion when parsing a malformed #recipe= URLEPSS CVE-2026-72911CRITICALERPNext: Possibility of server-side template injection due to missing validationEPSS CVE-2026-72910HIGHERPNext: Unauthorised modification of master data due to missing validationEPSS CVE-2026-72909HIGHERPNext: Broken Access Control on certain endpointsEPSS CVE-2026-72908MEDIUMERPNext: Possibility of SQL injection due to missing validationEPSS CVE-2026-72907MEDIUMERPNext: Broken Access Control on certain endpointEPSS CVE-2026-72906MEDIUMERPNext: Unauthorised triggering of automated emails due to missing validationEPSS CVE-2026-19411LOWShim/dp.c library: null-pointer dereference in is_removable_media_path() when devicepathtostr() returns nullEPSS