CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2026-48343

    Last Modified: 2 Aug 2026

    Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-48339

    Last Modified: 2 Aug 2026

    Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-48311

    Last Modified: 2 Aug 2026

    Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-48342

    Last Modified: 2 Aug 2026

    Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-48341

    Last Modified: 2 Aug 2026

    Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-48272

    Last Modified: 2 Aug 2026

    Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-48344

    Last Modified: 2 Aug 2026

    Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 14 Jul 2026
    5.8
    Medium

    CVE-2026-15738

    Last Modified: 16 Jul 2026

    Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2 might allow an authenticated remote user to intercept, spoof, or deny another namespace's gRPC traffic on a shared Gateway via a crafted HTTPRoute resource. To mitigate this issue, users should upgrade to version 3.4.2.

    Published: 14 Jul 2026
    6.3
    Medium

    CVE-2026-61520

    Last Modified: 28 Jul 2026

    Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image proxy that allows authenticated attackers to trigger internal HTTP requests by embedding attacker-controlled URLs in BBCode image tags, which the proxy fetches without validating resolved destination IPs against private address ranges, loopback, or link-local addresses. Attackers can leverage SMF's automatic HMAC signature generation for any embedded image URL to obtain valid signed proxy requests targeting internal services such as cloud instance metadata endpoints, internal web applications, and container network services.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-24272

    Last Modified: 31 Jul 2026

    NVIDIA TensorRT contains a vulnerability where an attacker might cause an overflow to a heap-based buffer. A successful exploit of this vulnerability might lead to code execution.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-24268

    Last Modified: 1 Aug 2026

    NVIDIA TensorRT contains a vulnerability where an attacker might cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-24238

    Last Modified: 1 Aug 2026

    NVIDIA TensorRT for contains a vulnerability where an attacker might cause an improper validation of array index. A successful exploit of this vulnerability might lead to code execution.

    Published: 14 Jul 2026
    5.3
    Medium

    CVE-2026-24227

    Last Modified: 31 Jul 2026

    NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution.

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-15778

    Last Modified: 22 Jul 2026

    Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-15776

    Last Modified: 25 Jul 2026

    Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-15777

    Last Modified: 29 Jul 2026

    Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-15775

    Last Modified: 25 Jul 2026

    Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

    Published: 14 Jul 2026
    8.3
    High

    CVE-2026-15774

    Last Modified: 25 Jul 2026

    Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 14 Jul 2026
    9.6
    Critical

    CVE-2026-15773

    Last Modified: 26 Jul 2026

    Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 14 Jul 2026
    8.3
    High

    CVE-2026-15772

    Last Modified: 26 Jul 2026

    Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 14 Jul 2026
    5.3
    Medium

    CVE-2026-15771

    Last Modified: 28 Jul 2026

    Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-15770

    Last Modified: 26 Jul 2026

    Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

    Published: 14 Jul 2026
    8.3
    High

    CVE-2026-15769

    Last Modified: 26 Jul 2026

    Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-15768

    Last Modified: 1 Aug 2026

    Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-15767

    Last Modified: 25 Jul 2026

    Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High)

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-15766

    Last Modified: 26 Jul 2026

    Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-15765

    Last Modified: 28 Jul 2026

    Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-15764

    Last Modified: 28 Jul 2026

    Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

    Published: 14 Jul 2026
    6.2
    Medium

    CVE-2026-24271

    Last Modified: 1 Aug 2026

    NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API, where an attacker could cause allocation of GPU resources without limits or throttling. A successful exploit of this vulnerability might lead to denial of service.

    Published: 14 Jul 2026
    6.2
    Medium

    CVE-2026-47475

    Last Modified: 28 Jul 2026

    NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a reachable assertion in the sampler thread. A successful exploit of this vulnerability might lead to denial of service.

    Published: 14 Jul 2026
    6.2
    Medium

    CVE-2026-47470

    Last Modified: 3 Aug 2026

    NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by local attack. A successful exploit of this vulnerability might lead to denial of service.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-48367

    Last Modified: 15 Jul 2026

    After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-48274

    Last Modified: 15 Jul 2026

    After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jul 2026
    9.1
    Critical

    CVE-2026-53486

    Last Modified: 27 Jul 2026

    The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets point, path containment used a string prefix comparison, and file modes failed to remove setuid, setgid, or sticky bits. This issue is fixed in @xhmikosr/decompress versions 10.2.1 and 11.1.3.

    Published: 14 Jul 2026
    6.3
    Medium

    CVE-2026-24226

    Last Modified: 31 Jul 2026

    NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

    Published: 14 Jul 2026
    6.4
    Medium

    CVE-2026-24259

    Last Modified: 1 Aug 2026

    NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

    Published: 14 Jul 2026
    6.4
    Medium

    CVE-2026-24220

    Last Modified: 31 Jul 2026

    NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A successful exploit of this vulnerability might lead to code execution.

    Published: 14 Jul 2026
    6.8
    Medium

    CVE-2026-24234

    Last Modified: 1 Aug 2026

    NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to denial of service and information disclosure.

    Published: 14 Jul 2026
    7.3
    High

    CVE-2026-24229

    Last Modified: 1 Aug 2026

    NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sending requests to the FastAPI server. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-48269

    Last Modified: 15 Jul 2026

    Premiere Pro is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-48369

    Last Modified: 15 Jul 2026

    Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-48270

    Last Modified: 15 Jul 2026

    Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jul 2026
    5.9
    Medium

    CVE-2026-48308

    Last Modified: 16 Jul 2026

    Premiere Pro is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 14 Jul 2026
    9.2
    Critical

    CVE-2026-15643

    Last Modified: 14 Jul 2026

    AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. A server-side request forgery in the pagination handling component in AWS awslabs.healthlake-mcp-server before 0.0.14 on all platforms might allow a remote authenticated user to exfiltrate AWS temporary security credentials to an arbitrary endpoint via a crafted next_token parameter. The server does not validate that pagination URLs point back to the expected HealthLake endpoint, allowing an actor to redirect subsequent requests to an actor-controlled server. Its recommended to upgrade to version 0.0.14 or later.

    Published: 14 Jul 2026
    8.7
    High

    CVE-2026-48801

    Last Modified: 15 Jul 2026

    linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails. Any service that synchronously renders untrusted Markdown with linkify:true on a request hot path can inherit a worker-process denial of service triggerable by a tens-of-KB request body. This issue is fixed in version 5.0.1.

    Published: 14 Jul 2026
    7.4
    High

    CVE-2026-47473

    Last Modified: 29 Jul 2026

    NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.

    Published: 14 Jul 2026
    6.3
    Medium

    CVE-2026-49978

    Last Modified: 21 Jul 2026

    DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside <template>.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-47471

    Last Modified: 31 Jul 2026

    NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a heap based buffer overflow. A successful exploit of this vulnerability might lead to information disclosure, data tampering, or denial of service.

    Published: 14 Jul 2026
    6.1
    Medium

    CVE-2026-49459

    Last Modified: 15 Jul 2026

    DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form> root when a descendant name clobbered properties checked by _isClobbered, because _forceRemove no-opped on the parent-less root and _sanitizeAttributes returned early. This issue is fixed in version 3.4.6.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-47472

    Last Modified: 1 Aug 2026

    NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, and denial of service.

    Published: 14 Jul 2026