CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-15770
6.5 MEDIUM

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted …

Jul 14, 2026
CVE-2026-15768
6.5 MEDIUM

Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. …

Jul 14, 2026
CVE-2026-15766
6.5 MEDIUM

Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted …

Jul 14, 2026
CVE-2026-15749
5.3 MEDIUM

A security flaw has been discovered in mastergo-design mastergo-magic-mcp up to 0.2.0. This issue affects the function execute of the file src/tools/get-c2d.ts of the component …

Jul 14, 2026
CVE-2026-50659
6.5 MEDIUM

Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.

Jul 14, 2026
CVE-2026-48784
6.1 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() …

Jul 14, 2026
CVE-2026-48761
6.1 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() …

Jul 14, 2026
CVE-2026-48760
6.1 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() …

Jul 14, 2026
CVE-2026-48747
5.3 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::validateSignature() parsed X-MOM-Webhook-Signature …

Jul 14, 2026
CVE-2026-48371
5.4 MEDIUM

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable …

Jul 14, 2026
CVE-2026-48355
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Jul 14, 2026
CVE-2026-48263
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Jul 14, 2026
CVE-2026-48262
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Jul 14, 2026
CVE-2026-48261
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Jul 14, 2026
CVE-2026-48260
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Jul 14, 2026
CVE-2026-48257
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Jul 14, 2026
CVE-2026-48255
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Jul 14, 2026
CVE-2026-48254
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Jul 14, 2026
CVE-2026-48253
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Jul 14, 2026
CVE-2026-48038
5.3 MEDIUM

joi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1, denial of service is possible via an untrapped exception …

Jul 14, 2026
CVE-2026-48000
4.3 MEDIUM

Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious …

Jul 14, 2026
CVE-2026-47999
4.8 MEDIUM

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable …

Jul 14, 2026
CVE-2026-47998
5.9 MEDIUM

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass …

Jul 14, 2026
CVE-2026-47997
5.9 MEDIUM

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass …

Jul 14, 2026
CVE-2026-47481
6.5 MEDIUM

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful …

Jul 14, 2026
CVE-2026-47212
5.3 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestParser::doParse() received …

Jul 14, 2026
CVE-2026-15714
6.5 MEDIUM

An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_multipart_input_stream_read_headers() function inside soup-multipart-input-stream.c, which does not adequately restrict …

Jul 14, 2026
CVE-2026-15713
5.9 MEDIUM

A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory context blocks under specific stream termination conditions, such as …

Jul 14, 2026
CVE-2026-45755
5.3 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::doParse() received the …

Jul 14, 2026
CVE-2026-45754
5.3 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet …

Jul 14, 2026
CVE-2026-45753
6.1 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlAttributeSanitizer::getSupportedAttributes() …

Jul 14, 2026
CVE-2026-45072
5.4 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.4.24 until 6.4.40, 7.4.12, and 8.0.12, the …

Jul 14, 2026
CVE-2026-45070
6.5 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader …

Jul 14, 2026
CVE-2026-45064
6.1 MEDIUM

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlSanitizer::parse() …

Jul 14, 2026
CVE-2026-15712
5.9 MEDIUM

A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tracking framework. When the library processes an HTTP/2 GOAWAY …

Jul 14, 2026
CVE-2026-58638
6.0 MEDIUM

Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

Jul 14, 2026
CVE-2026-58547
5.5 MEDIUM

Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-58546
6.5 MEDIUM

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

Jul 14, 2026
CVE-2026-58545
5.5 MEDIUM

Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.

Jul 14, 2026
CVE-2026-58543
6.3 MEDIUM

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical …

Jul 14, 2026
CVE-2026-58539
6.5 MEDIUM

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

Jul 14, 2026
CVE-2026-58535
6.5 MEDIUM

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

Jul 14, 2026
CVE-2026-58533
6.5 MEDIUM

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

Jul 14, 2026
CVE-2026-58528
6.8 MEDIUM

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

Jul 14, 2026
CVE-2026-57982
6.5 MEDIUM

Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.

Jul 14, 2026
CVE-2026-57973
6.3 MEDIUM

Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally.

Jul 14, 2026
CVE-2026-57095
6.2 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-57085
5.5 MEDIUM

Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-57084
5.5 MEDIUM

Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-57083
5.5 MEDIUM

Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.

Jul 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.