CVE Vulnerability Database
Search and browse 389,950 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47428 | CRITICAL | 9.6 | 0.4% | Jul 14, 2026 | Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__v... |
| CVE-2026-47423 | HIGH | 8.2 | 0.3% | Jul 14, 2026 | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedco... |
| CVE-2026-47212 | MEDIUM | 5.3 | 0.3% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1... |
| CVE-2026-45071 | HIGH | 7.5 | 0.5% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4... |
| CVE-2026-45068 | HIGH | 7.5 | 0.5% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4... |
| CVE-2026-15714 | MEDIUM | 6.5 | 0.4% | Jul 14, 2026 | An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_m... |
| CVE-2026-15713 | MEDIUM | 5.9 | 0.3% | Jul 14, 2026 | A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory con... |
| CVE-2026-15711 | HIGH | 7.5 | 0.4% | Jul 14, 2026 | A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rule... |
| CVE-2026-15709 | HIGH | 7.5 | 0.5% | Jul 14, 2026 | A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's deco... |
| CVE-2026-15410 | HIGH | 7.2 | 1.6% | Jul 14, 2026 | Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S... |
| CVE-2026-15409 | CRITICAL | 10 | 1.4% | Jul 14, 2026 | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A ... |
| CVE-2026-13001 | CRITICAL | 9.8 | — | Jul 14, 2026 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali... |
| CVE-2026-5040 | MEDIUM | 6.7 | 0.1% | Jul 14, 2026 | TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the passwo... |
| CVE-2026-47767 | CRITICAL | 9.8 | 0.4% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.... |
| CVE-2026-47305 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally. |
| CVE-2026-47304 | CRITICAL | 9.8 | 0.2% | Jul 14, 2026 | Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature ov... |
| CVE-2026-47303 | HIGH | 8.8 | 0.6% | Jul 14, 2026 | Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over... |
| CVE-2026-47302 | HIGH | 7.5 | 0.8% | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw... |
| CVE-2026-47301 | HIGH | 8.8 | 0.5% | Jul 14, 2026 | Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a ne... |
| CVE-2026-47300 | HIGH | 8.8 | 0.5% | Jul 14, 2026 | Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges... |
| CVE-2026-45755 | MEDIUM | 5.3 | — | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.... |
| CVE-2026-45754 | MEDIUM | 5.3 | 0.3% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1... |
| CVE-2026-45753 | MEDIUM | 6.1 | — | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until... |
| CVE-2026-45305 | HIGH | 7.5 | 0.7% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4... |
| CVE-2026-45304 | HIGH | 7.5 | 0.8% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4... |
