VYPR

CVEs

387,214 total · page 769 of 7,745

  • CVE-2026-48269HigJul 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Premiere Pro is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48125MedJul 14, 2026
    risk 0.27cvss 5.3epss 0.01

    UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1 until 2.0.10, a regular expression denial-of-service vulnerability exists when using the Client Hints API. By sending a crafted Sec-CH-UA-Model header to…

  • CVE-2026-47979MedJul 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2026-47976HigJul 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-47971HigJul 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Media Encoder is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-47475MedJul 14, 2026
    risk 0.00cvss 6.2epss 0.00

    NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a reachable assertion in the sampler thread. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2026-47473HigJul 14, 2026
    risk 0.00cvss 7.4epss 0.00

    NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.

  • CVE-2026-47472HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, and…

  • CVE-2026-47471HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a heap based buffer overflow. A successful exploit of this vulnerability might lead to information disclosure, data tampering, or denial of service.

  • CVE-2026-47470MedJul 14, 2026
    risk 0.00cvss 6.2epss 0.00

    NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by local attack. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2026-46644MedJul 14, 2026
    risk 0.38cvss —epss 0.01

    Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 until 1.38.1, symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload is empty or decodes to ASCII-only code points because Idn::process() does not…

  • CVE-2026-24272HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA TensorRT contains a vulnerability where an attacker might cause an overflow to a heap-based buffer. A successful exploit of this vulnerability might lead to code execution.

  • CVE-2026-24271MedJul 14, 2026
    risk 0.00cvss 6.2epss 0.00

    NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API, where an attacker could cause allocation of GPU resources without limits or throttling. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2026-24268HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA TensorRT contains a vulnerability where an attacker might cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution.

  • CVE-2026-24259MedJul 14, 2026
    risk 0.00cvss 6.4epss 0.00

    NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-24238HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA TensorRT for contains a vulnerability where an attacker might cause an improper validation of array index. A successful exploit of this vulnerability might lead to code execution.

  • CVE-2026-24234MedJul 14, 2026
    risk 0.00cvss 6.8epss 0.00

    NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to denial of service and information disclosure.

  • CVE-2026-24233HigJul 14, 2026
    risk 0.00cvss 8.4epss 0.00

    NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code…

  • CVE-2026-24229HigJul 14, 2026
    risk 0.00cvss 7.3epss 0.00

    NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sending requests to the FastAPI server. A successful exploit of this vulnerability might lead to…

  • CVE-2026-24227MedJul 14, 2026
    risk 0.00cvss 5.3epss 0.01

    NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution.

  • CVE-2026-24226MedJul 14, 2026
    risk 0.00cvss 6.3epss 0.00

    NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-24220MedJul 14, 2026
    risk 0.42cvss 6.4epss 0.00

    NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A successful exploit of this vulnerability might lead to code execution.

  • CVE-2026-15778MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.00

    Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-15777HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.00

    Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-15776HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-15775MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.00

    Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-15774HigJul 14, 2026
    risk 0.00cvss 8.3epss 0.00

    Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-15773CriJul 14, 2026
    risk 0.00cvss 9.6epss 0.00

    Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-15772HigJul 14, 2026
    risk 0.00cvss 8.3epss 0.00

    Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-15771MedJul 14, 2026
    risk 0.00cvss 5.3epss 0.00

    Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security…

  • CVE-2026-15770MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.00

    Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-15769HigJul 14, 2026
    risk 0.00cvss 8.3epss 0.00

    Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity:…

  • CVE-2026-15768MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.00

    Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-15767HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High)

  • CVE-2026-15766MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.00

    Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-15765HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-15764HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-15749MedJul 14, 2026
    risk 0.00cvss 5.3epss 0.00

    A security flaw has been discovered in mastergo-design mastergo-magic-mcp up to 0.2.0. This issue affects the function execute of the file src/tools/get-c2d.ts of the component mcp__C2d. Performing a manipulation of the argument filePath results in path traversal. The attack…

  • CVE-2026-15738HigJul 14, 2026
    risk 0.48cvss 8.5epss 0.01

    Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2 might allow an authenticated remote user to intercept, spoof, or deny another namespace's gRPC traffic on a shared Gateway via a crafted HTTPRoute resource. …

  • CVE-2026-15643HigJul 14, 2026
    risk 0.00cvss 7.3epss 0.00

    AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. A server-side request forgery in the pagination handling component in AWS awslabs.healthlake-mcp-server…

  • CVE-2026-53633CriJul 14, 2026
    risk 0.57cvss 9.8epss 0.01

    Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, allowing a remote client with exposed…

  • CVE-2026-50659MedJul 14, 2026
    risk 0.42cvss 6.5epss 0.01

    Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-50651HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50650HigJul 14, 2026
    risk 0.44cvss 7.8epss 0.00

    Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.

  • CVE-2026-50649HigJul 14, 2026
    risk 0.44cvss 7.8epss 0.04

    Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.

  • CVE-2026-50648HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50646HigJul 14, 2026
    risk 0.44cvss 7.8epss 0.04

    Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.

  • CVE-2026-50528HigJul 14, 2026
    risk 0.53cvss 8.2epss 0.01

    Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-50527HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50526HigJul 14, 2026
    risk 0.46cvss 7.0epss 0.00

    Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.