CVE Vulnerability Database

Search and browse 389,949 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-48298MEDIUM6.2CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a...
CVE-2026-48296MEDIUM6.2CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a...
CVE-2026-48295HIGH7.5CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclo...
CVE-2026-48290HIGH8.2CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary...
CVE-2026-48287HIGH7.4CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execut...
CVE-2026-48275HIGH8.6Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the c...
CVE-2026-47732MEDIUM6.5Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a ...
CVE-2026-47730MEDIUM5.4Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplat...
CVE-2026-46640HIGH8.8Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute synta...
CVE-2026-46639MEDIUM6.5Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::g...
CVE-2026-46638HIGH8.1Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previou...
CVE-2026-46637MEDIUM5.4Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra a...
CVE-2026-46635MEDIUM4.3Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), whic...
CVE-2026-46634CRITICAL9.8Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a ...
CVE-2026-46633CRITICAL9.8Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template n...
CVE-2026-46629MEDIUM6.5Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter ins...
CVE-2026-46628MEDIUM5.4Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, ca...
CVE-2026-46627MEDIUM6.5Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, m...
CVE-2026-45363CRITICAL9.1ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(t...
CVE-2026-42447MEDIUM5jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx-gui is affected by an HTML injection vulnerability in the Summary...
CVE-2026-42049HIGH8.4jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx inserts the android:versionName value from an AndroidManifest int...
CVE-2026-38450CRITICAL9.8An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name...
CVE-2026-21840LOW3.1HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, through careful syste...
CVE-2026-15750MEDIUM6.3A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the function z.string of t...
CVE-2025-56361HIGH7.5A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Lev...