Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-51808

Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the openhtj2k_decoder_impl::invoke, i…

Patch available
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.8
CVE-2026-51807

Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (fixed in v0.18.4) caused by m…

Patch available
Fix from $2,300 2026-07-14
Twig CRITICAL 9.1
CVE-2026-48807

Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replac…

Fix: 3.27.0+
Fix from $2,300 2026-07-14
Twig CRITICAL 9.1
CVE-2026-48806

Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP t…

Fix: 3.27.0+
Fix from $2,300 2026-07-14
Twig CRITICAL 9.1
CVE-2026-48805

Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state…

Fix: 3.27.0+
Fix from $2,300 2026-07-14
Illustrator CRITICAL 9.3
CVE-2026-48334

Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current use…

Fix: 29.8.9 / 30.6+
Fix from $2,300 2026-07-14
Twig CRITICAL 9.8
CVE-2026-46634

Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template…

Fix: 3.26.0+
Fix from $2,300 2026-07-14
Twig CRITICAL 9.8
CVE-2026-46633

Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is p…

Fix: 3.26.0+
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.1
CVE-2026-45363

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'H…

Patch available
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.8
CVE-2026-38450

An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of…

Mitigation only
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.1
CVE-2026-52101

An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote fun…

Mitigation only
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.1
CVE-2026-53486

The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target di…

Patch available
Fix from $2,300 2026-07-14
Coldfusion CRITICAL 9.0
CVE-2026-48327

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. …

Mitigation only
Fix from $2,300 2026-07-14
Coldfusion CRITICAL 9.3
CVE-2026-48325

ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context o…

Mitigation only
Fix from $2,300 2026-07-14
Coldfusion CRITICAL 9.1
CVE-2026-48324

ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in …

Mitigation only
Fix from $2,300 2026-07-14
Coldfusion CRITICAL 9.9
CVE-2026-48322

ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in…

Mitigation only
Fix from $2,300 2026-07-14
Coldfusion CRITICAL 9.3
CVE-2026-48321

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnera…

Mitigation only
Fix from $2,300 2026-07-14
Coldfusion CRITICAL 9.1
CVE-2026-48319EPSS 32%

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitr…

Mitigation only
Fix from $2,300 2026-07-14
Coldfusion CRITICAL 9.9
CVE-2026-48318

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrar…

Mitigation only
Fix from $2,300 2026-07-14
Coldfusion CRITICAL 9.6
CVE-2026-48284

ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user…

Mitigation only
Fix from $2,300 2026-07-14
Tensorrt CRITICAL 9.8
CVE-2026-24227

NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability…

Fix: 11.0+
Fix from $2,300 2026-07-14
Chrome CRITICAL 9.6
CVE-2026-15773

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a cr…

Fix: 150.0.7871.125+
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.8
CVE-2026-53633

Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarde…

Patch available
Fix from $2,300 2026-07-14
Experience Manager CRITICAL 9.6
CVE-2026-48359

Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary…

Fix: after 2020.5.0
Fix from $2,300 2026-07-14
Commerce CRITICAL 9.1
CVE-2026-48358

Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context o…

Fix: 1.21.0+
Fix from $2,300 2026-07-14
Commerce CRITICAL 9.3
CVE-2026-48356

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the c…

Fix: 1.21.0+
Fix from $2,300 2026-07-14
Experience Manager CRITICAL 9.6
CVE-2026-48259

Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the conte…

Fix: after 2020.5.0
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.6
CVE-2026-47428

Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCa…

Patch available
Fix from $2,300 2026-07-14
Sma6210 Firmware CRITICAL 10.0
CVE-2026-15409 KEVEPSS 84%

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attack…

Mitigation only
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.8
CVE-2026-13001

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle…

Patch available
Fix from $2,300 2026-07-14