CVE Vulnerability Database

Search and browse 389,950 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-47428CRITICAL9.6Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__v...
CVE-2026-47423HIGH8.2DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedco...
CVE-2026-47212MEDIUM5.3Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1...
CVE-2026-45071HIGH7.5Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4...
CVE-2026-45068HIGH7.5Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4...
CVE-2026-15714MEDIUM6.5An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_m...
CVE-2026-15713MEDIUM5.9A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory con...
CVE-2026-15711HIGH7.5A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rule...
CVE-2026-15709HIGH7.5A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's deco...
CVE-2026-15410HIGH7.2Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S...
CVE-2026-15409CRITICAL10A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A ...
CVE-2026-13001CRITICAL9.8The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali...
CVE-2026-5040MEDIUM6.7TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the passwo...
CVE-2026-47767CRITICAL9.8Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4....
CVE-2026-47305HIGH7.8Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.
CVE-2026-47304CRITICAL9.8Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature ov...
CVE-2026-47303HIGH8.8Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over...
CVE-2026-47302HIGH7.5Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw...
CVE-2026-47301HIGH8.8Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a ne...
CVE-2026-47300HIGH8.8Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges...
CVE-2026-45755MEDIUM5.3Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8....
CVE-2026-45754MEDIUM5.3Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1...
CVE-2026-45753MEDIUM6.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until...
CVE-2026-45305HIGH7.5Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4...
CVE-2026-45304HIGH7.5Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4...