CVE Database

52018+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-48254
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Jul 14, 2026
CVE-2026-48253
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Jul 14, 2026
CVE-2026-48038
5.3 MEDIUM

joi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1, denial of service is possible via an untrapped exception …

Jul 14, 2026
CVE-2026-48000
4.3 MEDIUM

Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious …

Jul 14, 2026
CVE-2026-47999
4.8 MEDIUM

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable …

Jul 14, 2026
CVE-2026-47998
5.9 MEDIUM

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass …

Jul 14, 2026
CVE-2026-47997
5.9 MEDIUM

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass …

Jul 14, 2026
CVE-2026-47481
6.5 MEDIUM

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful …

Jul 14, 2026
CVE-2026-47212
5.3 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestParser::doParse() received …

Jul 14, 2026
CVE-2026-15714
6.5 MEDIUM

An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_multipart_input_stream_read_headers() function inside soup-multipart-input-stream.c, which does not adequately restrict …

Jul 14, 2026
CVE-2026-15713
5.9 MEDIUM

A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory context blocks under specific stream termination conditions, such as …

Jul 14, 2026
CVE-2026-45755
5.3 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::doParse() received the …

Jul 14, 2026
CVE-2026-45754
5.3 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet …

Jul 14, 2026
CVE-2026-45753
6.1 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlAttributeSanitizer::getSupportedAttributes() …

Jul 14, 2026
CVE-2026-45072
5.4 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.4.24 until 6.4.40, 7.4.12, and 8.0.12, the …

Jul 14, 2026
CVE-2026-45070
6.5 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader …

Jul 14, 2026
CVE-2026-45064
6.1 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlSanitizer::parse() …

Jul 14, 2026
CVE-2026-15712
5.9 MEDIUM

A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tracking framework. When the library processes an HTTP/2 GOAWAY …

Jul 14, 2026
CVE-2026-58638
6.0 MEDIUM

Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

Jul 14, 2026
CVE-2026-58547
5.5 MEDIUM

Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-58546
6.5 MEDIUM

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

Jul 14, 2026
CVE-2026-58545
5.5 MEDIUM

Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.

Jul 14, 2026
CVE-2026-58543
6.3 MEDIUM

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical …

Jul 14, 2026
CVE-2026-58539
6.5 MEDIUM

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

Jul 14, 2026
CVE-2026-58535
6.5 MEDIUM

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

Jul 14, 2026
CVE-2026-58533
6.5 MEDIUM

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

Jul 14, 2026
CVE-2026-58528
6.8 MEDIUM

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

Jul 14, 2026
CVE-2026-57982
6.5 MEDIUM

Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.

Jul 14, 2026
CVE-2026-57973
6.3 MEDIUM

Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally.

Jul 14, 2026
CVE-2026-57095
6.2 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-57085
5.5 MEDIUM

Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-57084
5.5 MEDIUM

Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-57083
5.5 MEDIUM

Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-56649
5.9 MEDIUM

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-56195
5.5 MEDIUM

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-56192
5.5 MEDIUM

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-56184
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-56178
5.5 MEDIUM

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-56168
6.5 MEDIUM

Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.

Jul 14, 2026
CVE-2026-56157
5.4 MEDIUM

Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jul 14, 2026
CVE-2026-55898
6.1 MEDIUM

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-55145
6.3 MEDIUM

Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network.

Jul 14, 2026
CVE-2026-55142
5.5 MEDIUM

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-55139
5.5 MEDIUM

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-55138
5.5 MEDIUM

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-55135
4.6 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jul 14, 2026
CVE-2026-55124
5.5 MEDIUM

Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-55121
5.5 MEDIUM

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-55057
5.5 MEDIUM

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-55054
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

Jul 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.