69 Failles indexées
17 Critiques
14 Élevées
2 Ajoutées aujourd'hui

17 failles trouvées

filtres actifs
CVE-2026-31845
Critique 9.3

A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/tel/zadarma.php). The application directly reflects user-supplied input from the 'zd_echo' GET parameter into the HTTP response without proper sanitiza

CVE-2026-34621
Critique 9.6

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requi

EDB-52503
Critique

[local] ZSH 5.9 - RCE

EDB-52506
Critique

[webapps] React Server 19.2.0 - Remote Code Execution

EDB-52504
Critique

[webapps] Jumbo Website Manager - Remote Code Execution

EDB-52502
Critique

[webapps] FortiWeb 8.0.2 - Remote Code Execution

EDB-52500
Critique

[webapps] xibocms 3.3.4 - RCE

EDB-52497
Critique

[webapps] Horilla v1.3 - RCE

EDB-52489
Critique

[webapps] WBCE CMS 1.6.4 - Remote Code Execution

EDB-52488
Critique

[webapps] RiteCMS 3.1.0 - Authenticated Remote Code Execution

EDB-52481
Critique

[webapps] motionEye 0.43.1b4 - RCE

EDB-52477
Critique

[remote] Redis 8.0.2 - RCE

EDB-52475
Critique

[remote] Ingress-NGINX Admission Controller v1.11.1 - FD Injection to RCE

EDB-52473
Critique

[webapps] FortiWeb Fabric Connector 7.6.x - SQL Injection to Remote Code Execution

EDB-52472
Critique

[local] Docker Desktop 4.44.3 - Unauthenticated API Exposure

EDB-52464
Critique

[webapps] Chained Quiz 1.3.5 - Unauthenticated Insecure Direct Object Reference via Cookie

EDB-52463
Critique

[webapps] FreeBSD rtsold 15.x - Remote Code Execution via DNSSL