CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-47984
8.2 HIGH

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass …

Jul 14, 2026
CVE-2026-47737
7.5 HIGH

Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vulnerable to source IP spoofing when set_remote_address proxy_protocol: …

Jul 14, 2026
CVE-2026-47736
7.5 HIGH

Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, when PROXY protocol v1 support is enabled, Puma reads incoming …

Jul 14, 2026
CVE-2026-47482
7.5 HIGH

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory after effective lifetime. A successful exploit of …

Jul 14, 2026
CVE-2026-47481
6.5 MEDIUM

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful …

Jul 14, 2026
CVE-2026-47480
7.5 HIGH

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A successful exploit of this vulnerability might lead …

Jul 14, 2026
CVE-2026-47479
7.5 HIGH

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead …

Jul 14, 2026
CVE-2026-47478
7.5 HIGH

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file descriptor. A successful exploit of …

Jul 14, 2026
CVE-2026-47477
7.5 HIGH

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exploit of this vulnerability might …

Jul 14, 2026
CVE-2026-47476
7.5 HIGH

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead …

Jul 14, 2026
CVE-2026-47429
9.8 CRITICAL

Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing …

Jul 14, 2026
CVE-2026-47428
9.6 CRITICAL

Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCarrier query parameter inserted …

Jul 14, 2026
CVE-2026-47423
8.2 HIGH

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS …

Jul 14, 2026
CVE-2026-47212
5.3 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestParser::doParse() received …

Jul 14, 2026
CVE-2026-45071
7.5 HIGH

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Crawler::addXmlContent() …

Jul 14, 2026
CVE-2026-45068
7.5 HIGH

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, SendmailTransport …

Jul 14, 2026
CVE-2026-15714
6.5 MEDIUM

An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_multipart_input_stream_read_headers() function inside soup-multipart-input-stream.c, which does not adequately restrict …

Jul 14, 2026
CVE-2026-15713
5.9 MEDIUM

A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory context blocks under specific stream termination conditions, such as …

Jul 14, 2026
CVE-2026-15711
7.5 HIGH

A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that …

Jul 14, 2026
CVE-2026-15709
7.5 HIGH

A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an …

Jul 14, 2026
CVE-2026-15410
7.2 HIGH KEV

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could …

Jul 14, 2026
CVE-2026-15409
10.0 CRITICAL KEV

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance …

Jul 14, 2026
CVE-2026-13001
9.8 CRITICAL

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all …

Jul 14, 2026
CVE-2026-5040

TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or …

Jul 14, 2026
CVE-2026-47767
9.8 CRITICAL

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, …

Jul 14, 2026
CVE-2026-47305
7.8 HIGH

Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-47304
8.1 HIGH

Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.

Jul 14, 2026
CVE-2026-47303
8.8 HIGH

Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

Jul 14, 2026
CVE-2026-47302
7.5 HIGH

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

Jul 14, 2026
CVE-2026-47301
8.8 HIGH

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

Jul 14, 2026
CVE-2026-47300
8.8 HIGH

Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

Jul 14, 2026
CVE-2026-45755
5.3 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::doParse() received the …

Jul 14, 2026
CVE-2026-45754
5.3 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet …

Jul 14, 2026
CVE-2026-45753
6.1 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlAttributeSanitizer::getSupportedAttributes() …

Jul 14, 2026
CVE-2026-45305
7.5 HIGH

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser::cleanup() …

Jul 14, 2026
CVE-2026-45304
7.5 HIGH

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser …

Jul 14, 2026
CVE-2026-45133
7.5 HIGH

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when …

Jul 14, 2026
CVE-2026-45075
8.2 HIGH

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], …

Jul 14, 2026
CVE-2026-45073
7.3 HIGH

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, PdoAdapter::doClear() …

Jul 14, 2026
CVE-2026-45072
5.4 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.4.24 until 6.4.40, 7.4.12, and 8.0.12, the …

Jul 14, 2026
CVE-2026-45070
6.5 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader …

Jul 14, 2026
CVE-2026-45069
9.1 CRITICAL

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered …

Jul 14, 2026
CVE-2026-45064
6.1 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlSanitizer::parse() …

Jul 14, 2026
CVE-2026-45063
9.1 CRITICAL

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator …

Jul 14, 2026
CVE-2026-15720
8.6 HIGH

In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service.

Jul 14, 2026
CVE-2026-15712
5.9 MEDIUM

A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tracking framework. When the library processes an HTTP/2 GOAWAY …

Jul 14, 2026
CVE-2026-15642
3.3 LOW

Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an attacker with access …

Jul 14, 2026
CVE-2026-15641
7.1 HIGH

Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request …

Jul 14, 2026
CVE-2026-15637
7.5 HIGH

Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private …

Jul 14, 2026
CVE-2026-15058
3.1 LOW

Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct …

Jul 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.