Boletim Diário de Segurança

Busca em todas as edições

Agregado automaticamente, sem curadoria humana, a partir de fontes públicas: CISA KEV, NVD, EQSTLab e VEXDay. Cada alerta leva à sua fonte oficial.

1496 alertas em todas as edições, exibindo 421–450.

Alta · CVSS 7.1
NVD

CVE-2026-96816

Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions.

Alta · CVSS 7.1
NVD

CVE-2026-103242

A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-controlled, hex-decoded content — of attacker-chosen length — past the...

Alta · CVSS 7.1
NVD

CVE-2026-92869

An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination.

Alta · CVSS 7.1
NVD

CVE-2026-91832

The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every...

Alta · CVSS 7.1
NVD

CVE-2026-88797

The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any hosted on the WordPress.org repository.

Alta · CVSS 7.0
NVD

CVE-2026-93495

Improper initialization in an ASUS certain motherboard allows an physically proximate user to read or write arbitrary memory by inserting a specially crafted device.

Alta · CVSS 7.0
NVD

CVE-2026-102127

An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could potentially use a crafted message to read files accessible to the gateway service account, including...

Alta · CVSS 7.0
NVD

CVE-2026-47598

NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module event delivery path where an unprivileged local user could cause a use-after-free through a race between asynchronous event delivery and file close. A successful exploit of this vulnerability might lead to code execution,...

Alta · CVSS 7.0
NVD

CVE-2026-47596

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can write to read-only memory because the memory's permissions are not preserved. A successful exploit of this vulnerability might lead to code execution and escalation of privileges.

Alta · CVSS 7.0
NVD

CVE-2026-47582

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

Exploração ativa
CISA KEV

CVE-2026-86950

Apple Multiple Products Out-of-Bounds Write Vulnerability

Apple · Multiple Products

Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.

Crítica · CVSS 10.0
NVD

CVE-2026-71379

The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.

Crítica · CVSS 10.0
NVD

CVE-2026-96587

The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.