CVE Vulnerability Database
Search and browse 389,949 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61520 | HIGH | 7.7 | 0.3% | Jul 14, 2026 | Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery... |
| CVE-2026-59889 | MEDIUM | 6.5 | 0.4% | Jul 14, 2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From... |
| CVE-2026-53486 | CRITICAL | 9.1 | 0.6% | Jul 14, 2026 | The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files an... |
| CVE-2026-52101 | CRITICAL | 9.1 | 0.2% | Jul 14, 2026 | An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via ... |
| CVE-2026-52100 | HIGH | 7.5 | 0.5% | Jul 14, 2026 | Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to e... |
| CVE-2026-49978 | MEDIUM | 6.1 | 0.5% | Jul 14, 2026 | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE san... |
| CVE-2026-49855 | HIGH | 7.5 | 0.7% | Jul 14, 2026 | Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routin... |
| CVE-2026-49854 | MEDIUM | 5.3 | 0.4% | Jul 14, 2026 | Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tor... |
| CVE-2026-49853 | HIGH | 7.7 | 0.5% | Jul 14, 2026 | Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-cop... |
| CVE-2026-49477 | HIGH | 7.5 | 0.4% | Jul 14, 2026 | Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser ... |
| CVE-2026-49476 | HIGH | 7.5 | 0.4% | Jul 14, 2026 | Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser ... |
| CVE-2026-49459 | MEDIUM | 6.1 | 0.3% | Jul 14, 2026 | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(roo... |
| CVE-2026-49458 | MEDIUM | 6.1 | 0.3% | Jul 14, 2026 | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(nod... |
| CVE-2026-48816 | MEDIUM | 6.5 | 0.2% | Jul 14, 2026 | sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify deriv... |
| CVE-2026-48815 | HIGH | 7.5 | 0.2% | Jul 14, 2026 | sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certifi... |
| CVE-2026-48801 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the pack... |
| CVE-2026-48758 | MEDIUM | 5.4 | 0.3% | Jul 14, 2026 | sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.2.1, the preAuthEncoding fu... |
| CVE-2026-48370 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c... |
| CVE-2026-48369 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co... |
| CVE-2026-48367 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c... |
| CVE-2026-48366 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c... |
| CVE-2026-48344 | HIGH | 7.8 | 0.2% | Jul 14, 2026 | Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could resul... |
| CVE-2026-48343 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context ... |
| CVE-2026-48342 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in t... |
| CVE-2026-48341 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context ... |
