CVE Database

10684+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-5270
9.8 CRITICAL

An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue …

Jul 14, 2026
CVE-2026-5269
9.8 CRITICAL

In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these …

Jul 14, 2026
CVE-2026-51808
9.8 CRITICAL

Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the openhtj2k_decoder_impl::invoke, invoke_line_based, invoke_line_based_stream, and invoke_line_based_predecoded function in source/core/interface/decoder.cpp

Jul 14, 2026
CVE-2026-51807
9.8 CRITICAL

Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (fixed in v0.18.4) caused by missing bounds validation before coding-pass lengths are written to …

Jul 14, 2026
CVE-2026-48807
9.1 CRITICAL

Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace …

Jul 14, 2026
CVE-2026-48806
9.1 CRITICAL

Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to …

Jul 14, 2026
CVE-2026-48805
9.1 CRITICAL

Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), …

Jul 14, 2026
CVE-2026-48334
9.3 CRITICAL

Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Jul 14, 2026
CVE-2026-46634
9.8 CRITICAL

Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside …

Jul 14, 2026
CVE-2026-46633
9.8 CRITICAL

Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} …

Jul 14, 2026
CVE-2026-45363
9.1 CRITICAL

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts …

Jul 14, 2026
CVE-2026-38450
9.8 CRITICAL

An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of the …

Jul 14, 2026
CVE-2026-53486
9.1 CRITICAL

The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting …

Jul 14, 2026
CVE-2026-52101
9.1 CRITICAL

An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote function in upload.go

Jul 14, 2026
CVE-2026-48327
9.0 CRITICAL

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this …

Jul 14, 2026
CVE-2026-48325
9.3 CRITICAL

ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. …

Jul 14, 2026
CVE-2026-48324
9.1 CRITICAL

ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution …

Jul 14, 2026
CVE-2026-48322
9.6 CRITICAL

ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of …

Jul 14, 2026
CVE-2026-48321
9.3 CRITICAL

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and …

Jul 14, 2026
CVE-2026-48319
9.1 CRITICAL

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in …

Jul 14, 2026
CVE-2026-48318
9.9 CRITICAL

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. …

Jul 14, 2026
CVE-2026-48284
9.6 CRITICAL

ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Jul 14, 2026
CVE-2026-15773
9.6 CRITICAL

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a …

Jul 14, 2026
CVE-2026-53633
9.8 CRITICAL

Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw …

Jul 14, 2026
CVE-2026-48359
9.6 CRITICAL

Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the …

Jul 14, 2026
CVE-2026-48358
9.1 CRITICAL

Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the …

Jul 14, 2026
CVE-2026-48356
9.6 CRITICAL

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of …

Jul 14, 2026
CVE-2026-48259
9.6 CRITICAL

Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current …

Jul 14, 2026
CVE-2026-47429
9.8 CRITICAL

Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing …

Jul 14, 2026
CVE-2026-47428
9.6 CRITICAL

Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCarrier query parameter inserted …

Jul 14, 2026
CVE-2026-15409
10.0 CRITICAL KEV

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance …

Jul 14, 2026
CVE-2026-13001
9.8 CRITICAL

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all …

Jul 14, 2026
CVE-2026-47767
9.8 CRITICAL

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, …

Jul 14, 2026
CVE-2026-45069
9.1 CRITICAL

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered …

Jul 14, 2026
CVE-2026-45063
9.1 CRITICAL

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator …

Jul 14, 2026
CVE-2026-57092
9.9 CRITICAL

Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.

Jul 14, 2026
CVE-2026-56190
9.8 CRITICAL

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-56188
9.8 CRITICAL

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-56159
9.8 CRITICAL

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-55944
9.8 CRITICAL

Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-55040
9.1 CRITICAL KEV

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Jul 14, 2026
CVE-2026-55010
9.8 CRITICAL

Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-50518
9.8 CRITICAL

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-50447
9.8 CRITICAL

Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-50380
9.6 CRITICAL

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-15747
9.1 CRITICAL

Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and …

Jul 14, 2026
CVE-2026-59891
9.6 CRITICAL

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials() reads credentials from the Docker config file and selects an entry by …

Jul 14, 2026
CVE-2026-58644
9.8 CRITICAL KEV

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-55008
9.6 CRITICAL

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Jul 14, 2026
CVE-2026-54990
9.8 CRITICAL

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Jul 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.