CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2026-50646

    Last Modified: 5 Aug 2026

    Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.

    Published: 14 Jul 2026
    8.2
    High

    CVE-2026-50528

    Last Modified: 5 Aug 2026

    Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-50527

    Last Modified: 5 Aug 2026

    Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    7
    High

    CVE-2026-50526

    Last Modified: 5 Aug 2026

    Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-50525

    Last Modified: 5 Aug 2026

    Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-50524

    Last Modified: 5 Aug 2026

    Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    9.8
    Critical

    CVE-2026-47429

    Last Modified: 21 Jul 2026

    Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could also allow arbitrary script execution. This issue is fixed in versions 3.2.5 and 4.1.0.

    Published: 14 Jul 2026
    5.3
    Medium

    CVE-2026-48038

    Last Modified: 27 Jul 2026

    joi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1, denial of service is possible via an untrapped exception in services validating user-supplied JSON or object input with recursive link() schemas. When validate() is called without try/catch in a request handler, deeply nested input can trigger an unhandled RangeError and potentially crash the process; lower-impact paths using validateAsync() or try/catch produce a RangeError instead of a structured ValidationError. This issue is fixed in versions 17.13.4 and 18.2.1.

    Published: 14 Jul 2026
    5.3
    Medium

    CVE-2026-48761

    Last Modified: 3 Aug 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() omitted URL-bearing attributes on <object>, <applet>, <iframe>, and <img>, and <meta http-equiv="refresh"> URLs inside content bypassed URL sanitization, allowing explicitly enabled elements or attributes to pass javascript: and similar payloads into sanitized output. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.

    Published: 14 Jul 2026
    8.6
    High

    CVE-2026-48310

    Last Modified: 5 Aug 2026

    Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 14 Jul 2026
    9.6
    Critical

    CVE-2026-48259

    Last Modified: 5 Aug 2026

    Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to issue unauthorized server-side requests, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 14 Jul 2026
    9.6
    Critical

    CVE-2026-48359

    Last Modified: 5 Aug 2026

    Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to read sensitive files, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 14 Jul 2026
    5.4
    Medium

    CVE-2026-48263

    Last Modified: 5 Aug 2026

    Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

    Published: 14 Jul 2026
    5.4
    Medium

    CVE-2026-48260

    Last Modified: 5 Aug 2026

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 14 Jul 2026
    5.4
    Medium

    CVE-2026-48355

    Last Modified: 5 Aug 2026

    Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

    Published: 14 Jul 2026
    5.4
    Medium

    CVE-2026-48261

    Last Modified: 5 Aug 2026

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 14 Jul 2026
    5.4
    Medium

    CVE-2026-48253

    Last Modified: 5 Aug 2026

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 14 Jul 2026
    5.4
    Medium

    CVE-2026-48262

    Last Modified: 5 Aug 2026

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 14 Jul 2026
    8.6
    High

    CVE-2026-48252

    Last Modified: 5 Aug 2026

    Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 14 Jul 2026
    5.4
    Medium

    CVE-2026-48255

    Last Modified: 5 Aug 2026

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 14 Jul 2026
    5.4
    Medium

    CVE-2026-48257

    Last Modified: 5 Aug 2026

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 14 Jul 2026
    5.4
    Medium

    CVE-2026-48254

    Last Modified: 5 Aug 2026

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 14 Jul 2026
    6.3
    Medium

    CVE-2026-48747

    Last Modified: 27 Jul 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::validateSignature() parsed X-MOM-Webhook-Signature as algo=signature and passed the request-selected algorithm to hash_hmac(), allowing a signature algorithm downgrade instead of enforcing Mailomat's documented SHA-256 webhook signature. This issue is fixed in versions 7.4.13 and 8.0.13.

    Published: 14 Jul 2026
    8.7
    High

    CVE-2026-48489

    Last Modified: 27 Jul 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, DefaultAuthenticationFailureHandler honored the request-supplied _failure_path parameter when failure_forward: true was enabled, allowing an unauthenticated failing login request to dispatch a subrequest to access_control-protected GET routes that skipped firewall listeners. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.

    Published: 14 Jul 2026
    5.3
    Medium

    CVE-2026-48760

    Last Modified: 5 Aug 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() rejected raw BiDi formatting characters but not percent-encoded forms and used an ASCII-only whitespace check, allowing sanitized URLs to retain visual-spoofing characters that downstream consumers could decode or display. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.

    Published: 14 Jul 2026
    6.9
    Medium

    CVE-2026-48736

    Last Modified: 27 Jul 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and IpUtils::PRIVATE_SUBNETS omitted IPv6 transition prefixes such as 6to4, NAT64, Teredo, and IPv4-compatible IPv6, allowing attacker-supplied URLs to represent private IPv4 targets in forms that IpUtils::isPrivateIp() did not block. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.

    Published: 14 Jul 2026
    5.1
    Medium

    CVE-2026-48784

    Last Modified: 5 Aug 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr() dot-segment encoding that skipped every other chained ../ or ./ segment, allowing attacker-controlled route parameters to generate URLs that collapse to a different path under RFC 3986 normalization. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.

    Published: 14 Jul 2026
    8.7
    High

    CVE-2026-45068

    Last Modified: 27 Jul 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, SendmailTransport in -t mode appended recipient addresses to the sendmail command line without a -- end-of-options separator, allowing an address beginning with - to be interpreted as a sendmail command-line option instead of an address. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

    Published: 14 Jul 2026
    6.9
    Medium

    CVE-2026-47212

    Last Modified: 27 Jul 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestParser::doParse() received the configured webhook secret but ignored the X-Twilio-Signature HMAC header, allowing unauthenticated POST requests to inject forged Twilio status payloads. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.

    Published: 14 Jul 2026
    8.7
    High

    CVE-2026-45071

    Last Modified: 27 Jul 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Crawler::addXmlContent() set DOMDocument::$validateOnParse = true before loadXML(), re-enabling external entity resolution and allowing attacker-supplied XML to expand file:// entities such as local files. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

    Published: 14 Jul 2026
    6.9
    Medium

    CVE-2026-45755

    Last Modified: 27 Jul 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::doParse() received the configured webhook secret but ignored the X-Mt-Signature HMAC header, allowing unauthenticated POST requests to inject forged Mailtrap delivery, bounce, open, click, or spam events. This issue is fixed in versions 7.4.12 and 8.0.12.

    Published: 14 Jul 2026
    6.9
    Medium

    CVE-2026-45754

    Last Modified: 27 Jul 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet mailer bridge and LOX24 notifier bridge webhook parsers received configured webhook secrets but did not verify them, allowing unauthenticated POST requests to inject forged Mailjet and LOX24 event payloads. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.

    Published: 14 Jul 2026
    8.7
    High

    CVE-2026-45305

    Last Modified: 27 Jul 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser::cleanup() used regular expressions with overlapping quantifiers for YAML directive, comment, and document marker cleanup, allowing crafted input to make parsing hang for an arbitrarily long time. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

    Published: 14 Jul 2026
    8.7
    High

    CVE-2026-45304

    Last Modified: 27 Jul 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser resolved YAML collection aliases recursively, allowing a small untrusted YAML input to expand into a multi-gigabyte structure and exhaust memory. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-45069

    Last Modified: 27 Jul 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list to ClaimCheckerManager::check(), so a validly signed JWT that omitted those claims could pass verification. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-47305

    Last Modified: 15 Jul 2026

    Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.

    Published: 14 Jul 2026
    8.1
    High

    CVE-2026-47304

    Last Modified: 22 Jul 2026

    Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-47303

    Last Modified: 7 Aug 2026

    Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-47301

    Last Modified: 7 Aug 2026

    Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-47302

    Last Modified: 7 Aug 2026

    Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    8.2
    High

    CVE-2026-45133

    Last Modified: 15 Jul 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when the parser is exposed to attacker-controlled input, deeply nested mappings or sequences cause both the block-level (Parser::parseBlock()) and inline (Inline::parseSequence() / Inline::parseMapping()) parsers to recurse without a depth limit. A crafted document exhausts the PHP stack and crashes the worker. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

    Published: 14 Jul 2026
    8.3
    High

    CVE-2026-45075

    Last Modified: 27 Jul 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes can be configured for GET only, but Symfony routes HEAD requests to the GET handler while the attribute check is skipped, allowing protected controllers to execute and leak headers or perform side effects. This issue is fixed in versions 7.4.12 and 8.0.12.

    Published: 14 Jul 2026
    8.3
    High

    CVE-2026-47767

    Last Modified: 27 Jul 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on empty($_GET), but parse_str() and the web SAPI can disagree, allowing a crafted query string to leave $_GET empty while $_SERVER['argv'] still carries attacker-controlled --env or --no-debug flags that change APP_ENV or APP_DEBUG. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

    Published: 14 Jul 2026
    2.3
    Low

    CVE-2026-45064

    Last Modified: 5 Aug 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlSanitizer::parse() passes Unicode explicit-direction BiDi formatting characters through into sanitized href and src attributes, allowing sanitized content to display a link destination that visually differs from the actual destination and enabling phishing-style visual spoofing. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.

    Published: 14 Jul 2026
    9.1
    Critical

    CVE-2026-45063

    Last Modified: 15 Jul 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress= anywhere in the distinguished name, allowing an attacker with a trusted certificate containing emailAddress=victim inside another RDN value such as CN to authenticate as the victim. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

    Published: 14 Jul 2026
    6.3
    Medium

    CVE-2026-45070

    Last Modified: 27 Jul 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader validates and encodes parameter values but emits parameter names verbatim, allowing a caller that derives a parameter name from untrusted input to include CRLF or other non-token bytes and inject additional headers into rendered structured mail headers such as Content-Type or Content-Disposition. This issue is reported as fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

    Published: 14 Jul 2026
    6.3
    Medium

    CVE-2026-45073

    Last Modified: 27 Jul 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, PdoAdapter::doClear() builds a DELETE statement using a namespace derived from the caller-supplied $prefix without binding or escaping it, allowing a caller able to influence $prefix to break out of the LIKE literal and alter query semantics or deletion scope. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

    Published: 14 Jul 2026
    2.1
    Low

    CVE-2026-45753

    Last Modified: 5 Aug 2026

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlAttributeSanitizer::getSupportedAttributes() omits URL-valued attributes including action, formaction, poster, and cite, so configurations that admit those attributes can leave javascript: URIs unsanitized and enable XSS when the resulting HTML is rendered or a victim submits a form or clicks a button. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.

    Published: 14 Jul 2026
    8.6
    High

    CVE-2026-15720

    Last Modified: 15 Jul 2026

    In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-47300

    Last Modified: 7 Aug 2026

    Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

    Published: 14 Jul 2026