CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-48806
9.1 CRITICAL

Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to …

Jul 14, 2026
CVE-2026-48805
9.1 CRITICAL

Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), …

Jul 14, 2026
CVE-2026-48357
6.2 MEDIUM

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust …

Jul 14, 2026
CVE-2026-48354
6.2 MEDIUM

CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability …

Jul 14, 2026
CVE-2026-48353
5.5 MEDIUM

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability …

Jul 14, 2026
CVE-2026-48352
7.5 HIGH

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to …

Jul 14, 2026
CVE-2026-48351
7.5 HIGH

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to …

Jul 14, 2026
CVE-2026-48337
7.8 HIGH

Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this …

Jul 14, 2026
CVE-2026-48336
7.8 HIGH

Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this …

Jul 14, 2026
CVE-2026-48335
7.8 HIGH

Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this …

Jul 14, 2026
CVE-2026-48334
9.3 CRITICAL

Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Jul 14, 2026
CVE-2026-48312
6.8 MEDIUM

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability …

Jul 14, 2026
CVE-2026-48302
6.2 MEDIUM

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to …

Jul 14, 2026
CVE-2026-48298
6.2 MEDIUM

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this …

Jul 14, 2026
CVE-2026-48296
6.2 MEDIUM

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this …

Jul 14, 2026
CVE-2026-48295
7.5 HIGH

CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclosure of sensitive information. An attacker could leverage this vulnerability …

Jul 14, 2026
CVE-2026-48290
8.2 HIGH

CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current …

Jul 14, 2026
CVE-2026-48287
7.4 HIGH

CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. …

Jul 14, 2026
CVE-2026-48275
8.6 HIGH

Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Jul 14, 2026
CVE-2026-47732
6.5 MEDIUM

Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), …

Jul 14, 2026
CVE-2026-47730
5.4 MEDIUM

Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or …

Jul 14, 2026
CVE-2026-46640
8.8 HIGH

Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute syntax can concatenate an attacker-controlled string into a MacroReferenceExpression …

Jul 14, 2026
CVE-2026-46639
6.5 MEDIUM

Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with the sandbox argument hardcoded to false, disabling property and …

Jul 14, 2026
CVE-2026-46638
8.1 HIGH

Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previously loaded outside the …

Jul 14, 2026
CVE-2026-46637
5.4 MEDIUM

Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to …

Jul 14, 2026
CVE-2026-46635
4.3 MEDIUM

Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), which reads public and magic properties …

Jul 14, 2026
CVE-2026-46634
9.8 CRITICAL

Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside …

Jul 14, 2026
CVE-2026-46633
9.8 CRITICAL

Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} …

Jul 14, 2026
CVE-2026-46629
6.5 MEDIUM

Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter instances in arrays keyed by template-controlled filter arguments such as …

Jul 14, 2026
CVE-2026-46628
5.4 MEDIUM

Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit …

Jul 14, 2026
CVE-2026-46627
6.5 MEDIUM

Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, …

Jul 14, 2026
CVE-2026-45363
9.1 CRITICAL

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts …

Jul 14, 2026
CVE-2026-42447
3.6 LOW

jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx-gui is affected by an HTML injection vulnerability in the Summary tab because SummaryNode.java appends …

Jul 14, 2026
CVE-2026-42049

jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx inserts the android:versionName value from an AndroidManifest into the generated app/build.gradle Groovy template without …

Jul 14, 2026
CVE-2026-38450
9.8 CRITICAL

An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of the …

Jul 14, 2026
CVE-2026-21840
3.1 LOW

HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, through careful system control and response time monitoring, to perform …

Jul 14, 2026
CVE-2026-15750
6.3 MEDIUM

A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the function z.string of the file src/tools/get-component-link.ts of the component mcp__getComponentLink. Executing …

Jul 14, 2026
CVE-2025-56361
7.5 HIGH

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Level Control cluster's server tick logic (`emberAfLevelControlClusterServerTickCallback`). When a …

Jul 14, 2026
CVE-2026-61520
7.7 HIGH

Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image proxy that …

Jul 14, 2026
CVE-2026-59889
6.5 MEDIUM

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON …

Jul 14, 2026
CVE-2026-53486
9.1 CRITICAL

The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting …

Jul 14, 2026
CVE-2026-52101
9.1 CRITICAL

An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote function in upload.go

Jul 14, 2026
CVE-2026-52100
7.5 HIGH

Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to execute arbitrary code via the uploadPutHandler function

Jul 14, 2026
CVE-2026-49978

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an …

Jul 14, 2026
CVE-2026-49855
7.5 HIGH

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an …

Jul 14, 2026
CVE-2026-49854
5.3 MEDIUM

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask …

Jul 14, 2026
CVE-2026-49853
7.7 HIGH

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, …

Jul 14, 2026
CVE-2026-49477
7.5 HIGH

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains …

Jul 14, 2026
CVE-2026-49476
7.5 HIGH

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates …

Jul 14, 2026
CVE-2026-49459
6.1 MEDIUM

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on …

Jul 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.