CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-50650
7.8 HIGH

Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-50649
7.8 HIGH

Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-50648
7.5 HIGH

Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.

Jul 14, 2026
CVE-2026-50646
7.8 HIGH

Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-50528
8.2 HIGH

Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

Jul 14, 2026
CVE-2026-50527
7.5 HIGH

Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.

Jul 14, 2026
CVE-2026-50526
7.0 HIGH

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.

Jul 14, 2026
CVE-2026-50525
7.5 HIGH

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

Jul 14, 2026
CVE-2026-50524
7.5 HIGH

Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.

Jul 14, 2026
CVE-2026-48784
6.1 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() …

Jul 14, 2026
CVE-2026-48761
6.1 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() …

Jul 14, 2026
CVE-2026-48760
6.1 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() …

Jul 14, 2026
CVE-2026-48747
5.3 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::validateSignature() parsed X-MOM-Webhook-Signature …

Jul 14, 2026
CVE-2026-48736
8.6 HIGH

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, …

Jul 14, 2026
CVE-2026-48489
7.5 HIGH

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, DefaultAuthenticationFailureHandler …

Jul 14, 2026
CVE-2026-48371
5.4 MEDIUM

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable …

Jul 14, 2026
CVE-2026-48359
9.6 CRITICAL

Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the …

Jul 14, 2026
CVE-2026-48358
9.1 CRITICAL

Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the …

Jul 14, 2026
CVE-2026-48356
9.6 CRITICAL

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of …

Jul 14, 2026
CVE-2026-48355
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Jul 14, 2026
CVE-2026-48350
8.6 HIGH

Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in …

Jul 14, 2026
CVE-2026-48349
8.1 HIGH

Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on …

Jul 14, 2026
CVE-2026-48348
7.7 HIGH

Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on …

Jul 14, 2026
CVE-2026-48347
7.7 HIGH

Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code …

Jul 14, 2026
CVE-2026-48346
7.9 HIGH

Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Jul 14, 2026
CVE-2026-48345
8.2 HIGH

Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code …

Jul 14, 2026
CVE-2026-48310
8.6 HIGH

Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file …

Jul 14, 2026
CVE-2026-48263
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Jul 14, 2026
CVE-2026-48262
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Jul 14, 2026
CVE-2026-48261
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Jul 14, 2026
CVE-2026-48260
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Jul 14, 2026
CVE-2026-48259
9.6 CRITICAL

Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current …

Jul 14, 2026
CVE-2026-48257
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Jul 14, 2026
CVE-2026-48255
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Jul 14, 2026
CVE-2026-48254
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Jul 14, 2026
CVE-2026-48253
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Jul 14, 2026
CVE-2026-48252
8.6 HIGH

Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. An attacker could leverage …

Jul 14, 2026
CVE-2026-48069
7.5 HIGH

@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid …

Jul 14, 2026
CVE-2026-48068
7.5 HIGH

@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid …

Jul 14, 2026
CVE-2026-48038
5.3 MEDIUM

joi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1, denial of service is possible via an untrapped exception …

Jul 14, 2026
CVE-2026-48001
3.7 LOW

Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited disclosure of sensitive information. Exploit depends on conditions beyond the …

Jul 14, 2026
CVE-2026-48000
4.3 MEDIUM

Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious …

Jul 14, 2026
CVE-2026-47999
4.8 MEDIUM

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable …

Jul 14, 2026
CVE-2026-47998
5.9 MEDIUM

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass …

Jul 14, 2026
CVE-2026-47997
5.9 MEDIUM

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass …

Jul 14, 2026
CVE-2026-47996
7.6 HIGH

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to …

Jul 14, 2026
CVE-2026-47995
8.1 HIGH

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable …

Jul 14, 2026
CVE-2026-47994
8.7 HIGH

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable …

Jul 14, 2026
CVE-2026-47992
7.2 HIGH

Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code …

Jul 14, 2026
CVE-2026-47988
8.6 HIGH

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass …

Jul 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.