Todas as CVEs dos últimos seis meses, atualizadas diariamente.
Vulnerabilidades publicadas direto da National Vulnerability Database, com gravidade, classe CWE e produtos afetados. Pesquise, filtre e veja o que saiu hoje.
- 341 publicadas nas últimas 24 horas
- 2.848 nos últimos 7 dias
- 58.469 nos últimos seis meses
Fonte: NVD (National Vulnerability Database) · Atualizado em 24 de set. de 2026
Exibindo 5 de 5
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.
IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features.
A vulnerability was determined in zhinianboke xianyu-auto-reply on Server. Affected by this vulnerability is an unknown functionality of the file /api/v1/payment/withdraw/review?action=approve. Executing a manipulation can lead to trusting http permission meth
IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 are vulnerable to a cross-site request forgery attack, because they use the HTTP method `GET` to change state on the ser
ChurchCRM is an open-source church management system. Prior to 7.3.2, top-level cross-site GET navigation from an attacker-controlled page to FundRaiserDelete.php, PropertyTypeDelete.php, or NoteDelete.php causes a logged-in ChurchCRM user with the relevant ro
Encontre a falha antes de um atacante.
Entre com o GitHub e rode sua primeira auditoria em menos de um minuto. O plano gratuito não exige cartão de crédito.