CVE Feed

    Dashboard / CVE

    8.4
    High

    CVE-2026-24233

    Last Modified: 1 Aug 2026

    NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-47971

    Last Modified: 2 Aug 2026

    Media Encoder is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-48366

    Last Modified: 2 Aug 2026

    Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-47976

    Last Modified: 2 Aug 2026

    Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-47979

    Last Modified: 2 Aug 2026

    Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-48370

    Last Modified: 15 Jul 2026

    Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jul 2026
    6.1
    Medium

    CVE-2026-49458

    Last Modified: 16 Jul 2026

    DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks used parent-realm constructors, causing instanceof checks for forms, named node maps, document fragments, and elements to fail and skip clobber, template-content, and shadow-DOM sanitization branches so executable markup could survive. This issue is fixed in version 3.4.6.

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-59889

    Last Modified: 16 Jul 2026

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and calls prop.deserializeAndSet() without a prop.visibleInView(ctxt.getActiveView()) guard, allowing a property annotated with both @JsonView and @JsonUnwrapped to be written from attacker JSON under a less-privileged active view. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1.

    Published: 14 Jul 2026
    8.2
    High

    CVE-2026-47423

    Last Modified: 16 Jul 2026

    DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside <selectedcontent> is returned. This issue is fixed in version 3.4.5.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-47736

    Last Modified: 15 Jul 2026

    Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, when PROXY protocol v1 support is enabled, Puma reads incoming bytes into an internal buffer while waiting for CRLF to determine whether a PROXY v1 line is present, allowing an attacker that continuously sends bytes without CRLF to cause unbounded in-process memory growth and additional CPU cost from repeatedly scanning the growing buffer. This issue is fixed in versions 7.2.1 and 8.0.2.

    Published: 14 Jul 2026
    7.9
    High

    CVE-2026-48346

    Last Modified: 27 Jul 2026

    Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

    Published: 14 Jul 2026
    8.2
    High

    CVE-2026-48345

    Last Modified: 27 Jul 2026

    Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

    Published: 14 Jul 2026
    7.7
    High

    CVE-2026-48347

    Last Modified: 27 Jul 2026

    Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

    Published: 14 Jul 2026
    8.1
    High

    CVE-2026-48349

    Last Modified: 27 Jul 2026

    Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 14 Jul 2026
    7.7
    High

    CVE-2026-48348

    Last Modified: 27 Jul 2026

    Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

    Published: 14 Jul 2026
    8.6
    High

    CVE-2026-48350

    Last Modified: 27 Jul 2026

    Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to access sensitive files or directories outside the intended restrictions. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-47482

    Last Modified: 1 Aug 2026

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory after effective lifetime. A successful exploit of this vulnerability might lead to denial of service.

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-47481

    Last Modified: 31 Jul 2026

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-47480

    Last Modified: 31 Jul 2026

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A successful exploit of this vulnerability might lead to denial of service.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-47479

    Last Modified: 31 Jul 2026

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-47478

    Last Modified: 31 Jul 2026

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file descriptor. A successful exploit of this vulnerability might lead to denial of service.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-47737

    Last Modified: 15 Jul 2026

    Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vulnerable to source IP spoofing when set_remote_address proxy_protocol: :v1 is enabled and persistent connections are used because Puma incorrectly re-parses PROXY protocol headers after each keep-alive request on the same connection, allowing an attacker to inject a second PROXY header and overwrite REMOTE_ADDR. This issue is fixed in versions 7.2.1 and 8.0.2.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-47477

    Last Modified: 1 Aug 2026

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exploit of this vulnerability might lead to denial of service.

    Published: 14 Jul 2026
    8.2
    High

    CVE-2026-47984

    Last Modified: 5 Aug 2026

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does not require user interaction.

    Published: 14 Jul 2026
    5.9
    Medium

    CVE-2026-47997

    Last Modified: 3 Aug 2026

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.

    Published: 14 Jul 2026
    8.6
    High

    CVE-2026-47988

    Last Modified: 4 Aug 2026

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.

    Published: 14 Jul 2026
    4.8
    Medium

    CVE-2026-47999

    Last Modified: 3 Aug 2026

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

    Published: 14 Jul 2026
    9.1
    Critical

    CVE-2026-48358

    Last Modified: 3 Aug 2026

    Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 14 Jul 2026
    9.3
    Critical

    CVE-2026-48356

    Last Modified: 3 Aug 2026

    Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

    Published: 14 Jul 2026
    5.9
    Medium

    CVE-2026-47998

    Last Modified: 28 Aug 2026

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.

    Published: 14 Jul 2026
    6.1
    Medium

    CVE-2026-48000

    Last Modified: 6 Aug 2026

    Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site. Exploitation of this issue requires user interaction in that a victim must click on a malicious link. Scope is changed.

    Published: 14 Jul 2026
    8.1
    High

    CVE-2026-47995

    Last Modified: 3 Aug 2026

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

    Published: 14 Jul 2026
    3.7
    Low

    CVE-2026-48001

    Last Modified: 3 Aug 2026

    Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited disclosure of sensitive information. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.

    Published: 14 Jul 2026
    5.4
    Medium

    CVE-2026-48371

    Last Modified: 3 Aug 2026

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

    Published: 14 Jul 2026
    6.8
    Medium

    CVE-2026-47996

    Last Modified: 4 Aug 2026

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. A high-privileged attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 14 Jul 2026
    8.7
    High

    CVE-2026-47994

    Last Modified: 3 Aug 2026

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

    Published: 14 Jul 2026
    7.2
    High

    CVE-2026-47992

    Last Modified: 3 Aug 2026

    Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to execute malicious SQL commands, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-47476

    Last Modified: 4 Sept 2026

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.

    Published: 14 Jul 2026
    7.2
    High

    CVE-2026-15410

    Last Modified: 24 Aug 2026

    Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-48069

    Last Modified: 3 Aug 2026

    @grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming compressed message can cause a client or server process that uses @grpc/grpc-js to crash. This issue is fixed in versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4.

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-50659

    Last Modified: 5 Aug 2026

    Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-50651

    Last Modified: 5 Aug 2026

    Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-48068

    Last Modified: 3 Aug 2026

    @grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming HTTP/2 stream initiation can cause a server process created using @grpc/grpc-js to crash. This issue is fixed in versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4.

    Published: 14 Jul 2026
    10
    Critical

    CVE-2026-15409

    Last Modified: 24 Aug 2026

    A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

    Published: 14 Jul 2026
    9.8
    Critical

    CVE-2026-53633

    Last Modified: 29 Jul 2026

    Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, allowing a remote client with exposed browser API metadata to use CDP Page.setDownloadBehavior and Runtime.evaluate to overwrite vite.config.ts and execute attacker-controlled Node.js code. This issue is fixed in versions 3.2.5, 4.1.8, and 5.0.0-beta.

    Published: 14 Jul 2026
    9.8
    Critical

    CVE-2026-13001

    Last Modified: 5 Aug 2026

    The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 14 Jul 2026
    9.6
    Critical

    CVE-2026-47428

    Last Modified: 15 Jul 2026

    Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCarrier query parameter inserted directly into an inline module script, allowing a crafted browser-runner URL to execute arbitrary JavaScript in the Vitest server origin and recover VITEST_API_TOKEN for authenticated API calls. This issue is fixed in versions 4.1.6 and 5.0.0-beta.3.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50650

    Last Modified: 5 Aug 2026

    Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50649

    Last Modified: 5 Aug 2026

    Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-50648

    Last Modified: 5 Aug 2026

    Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026