Son altı ayın tüm CVE kayıtları, her gün güncellenir.
Ulusal Güvenlik Açığı Veritabanı’ndan doğrudan gelen yayımlanmış açıklar; önem derecesi, CWE sınıfı ve etkilenen ürünlerle. Arayın, filtreleyin, bugün ne çıktığını görün.
- Son 24 saatte 362 kayıt
- Son 7 günde 2.933 kayıt
- Son altı ayda 58.248 kayıt
Kaynak: NVD (Ulusal Güvenlik Açığı Veritabanı) · Güncellenme: 23 Eyl 2026
5 kayıttan 5 tanesi gösteriliyor
HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data passed in this manner can be exposed because it may end up stored in unintended locatio
HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force , automated attacks & account enumeration
GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. The random method creates the challenge text used for the CAPTCHA by sampling characters from an array using Perl's built-in rand function, and generates a (by default) six-characte
Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remote attackers to defeat challenge controls by exploiting limited complexity and predictable character sets in generated CAPTCHA images. Attac
WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/getCaptcha.php` accepts the CAPTCHA length (`ql`) directly from the query string with no clamping or sanitization, letting any unauthenticated client force the server to generat
CWE-804wwbn avideo
Açığı bir saldırgandan önce siz bulun.
GitHub ile giriş yapın ve ilk denetiminizi bir dakikadan kısa sürede başlatın. Ücretsiz plan için kredi kartı gerekmez.