CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-24233
8.4 HIGH

NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of …

Jul 14, 2026
CVE-2026-24229
7.3 HIGH

NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sending …

Jul 14, 2026
CVE-2026-24227
5.3 MEDIUM

NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Jul 14, 2026
CVE-2026-24226
6.3 MEDIUM

NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead …

Jul 14, 2026
CVE-2026-24220
6.4 MEDIUM

NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A …

Jul 14, 2026
CVE-2026-15778
6.5 MEDIUM

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to bypass …

Jul 14, 2026
CVE-2026-15777
7.5 HIGH

Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific …

Jul 14, 2026
CVE-2026-15776
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Jul 14, 2026
CVE-2026-15775
6.5 MEDIUM

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium …

Jul 14, 2026
CVE-2026-15774
8.3 HIGH

Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jul 14, 2026
CVE-2026-15773
9.6 CRITICAL

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a …

Jul 14, 2026
CVE-2026-15772
8.3 HIGH

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 14, 2026
CVE-2026-15771
5.3 MEDIUM

Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process …

Jul 14, 2026
CVE-2026-15770
6.5 MEDIUM

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted …

Jul 14, 2026
CVE-2026-15769
8.3 HIGH

Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who had compromised the …

Jul 14, 2026
CVE-2026-15768
6.5 MEDIUM

Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. …

Jul 14, 2026
CVE-2026-15767
8.8 HIGH

Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via …

Jul 14, 2026
CVE-2026-15766
6.5 MEDIUM

Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted …

Jul 14, 2026
CVE-2026-15765
7.5 HIGH

Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Jul 14, 2026
CVE-2026-15764
7.5 HIGH

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific …

Jul 14, 2026
CVE-2026-15749
5.3 MEDIUM

A security flaw has been discovered in mastergo-design mastergo-magic-mcp up to 0.2.0. This issue affects the function execute of the file src/tools/get-c2d.ts of the component …

Jul 14, 2026
CVE-2026-15738
8.5 HIGH

Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2 might allow an authenticated remote user to intercept, …

Jul 14, 2026
CVE-2026-15643
7.3 HIGH

AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. A server-side request …

Jul 14, 2026
CVE-2026-53633
9.8 CRITICAL

Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw …

Jul 14, 2026
CVE-2026-50659
6.5 MEDIUM

Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.

Jul 14, 2026
CVE-2026-50651
7.5 HIGH

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

Jul 14, 2026
CVE-2026-50650
7.8 HIGH

Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-50649
7.8 HIGH

Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-50648
7.5 HIGH

Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.

Jul 14, 2026
CVE-2026-50646
7.8 HIGH

Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-50528
8.2 HIGH

Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

Jul 14, 2026
CVE-2026-50527
7.5 HIGH

Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.

Jul 14, 2026
CVE-2026-50526
7.0 HIGH

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.

Jul 14, 2026
CVE-2026-50525
7.5 HIGH

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

Jul 14, 2026
CVE-2026-50524
7.5 HIGH

Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.

Jul 14, 2026
CVE-2026-48784
6.1 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() …

Jul 14, 2026
CVE-2026-48761
6.1 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() …

Jul 14, 2026
CVE-2026-48760
6.1 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() …

Jul 14, 2026
CVE-2026-48747
5.3 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::validateSignature() parsed X-MOM-Webhook-Signature …

Jul 14, 2026
CVE-2026-48736
8.6 HIGH

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, …

Jul 14, 2026
CVE-2026-48489
7.5 HIGH

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, DefaultAuthenticationFailureHandler …

Jul 14, 2026
CVE-2026-48371
5.4 MEDIUM

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable …

Jul 14, 2026
CVE-2026-48359
9.6 CRITICAL

Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the …

Jul 14, 2026
CVE-2026-48358
9.1 CRITICAL

Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the …

Jul 14, 2026
CVE-2026-48356
9.6 CRITICAL

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of …

Jul 14, 2026
CVE-2026-48355
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Jul 14, 2026
CVE-2026-48350
8.6 HIGH

Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in …

Jul 14, 2026
CVE-2026-48349
8.1 HIGH

Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on …

Jul 14, 2026
CVE-2026-48348
7.7 HIGH

Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on …

Jul 14, 2026
CVE-2026-48347
7.7 HIGH

Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code …

Jul 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.