Todas as CVEs dos últimos seis meses, atualizadas diariamente.
Vulnerabilidades publicadas direto da National Vulnerability Database, com gravidade, classe CWE e produtos afetados. Pesquise, filtre e veja o que saiu hoje.
- 296 publicadas nas últimas 24 horas
- 2.795 nos últimos 7 dias
- 58.275 nos últimos seis meses
Fonte: NVD (National Vulnerability Database) · Atualizado em 23 de set. de 2026
Exibindo 3 de 3
fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parser in version 4.1.3. In versions 4.1.3 and 4.1.4, the mailto parser compares each query field name to the reserved names to, subject, and bod
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr() dot-segment encoding that skipped every other chained ../ or ./ segment, allo
When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer. Note: Software versions which have reached En
Encontre a falha antes de um atacante.
Entre com o GitHub e rode sua primeira auditoria em menos de um minuto. O plano gratuito não exige cartão de crédito.