VYPR

CVEs

387,214 total · page 770 of 7,745

  • CVE-2026-50525HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50524HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.

  • CVE-2026-48784MedJul 14, 2026
    risk 0.33cvss 6.1epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr() dot-segment encoding that skipped every other chained ../ or ./ segment, allowing…

  • CVE-2026-48761MedJul 14, 2026
    risk 0.33cvss 6.1epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() omitted URL-bearing attributes on , , , and , and <meta…

  • CVE-2026-48760MedJul 14, 2026
    risk 0.33cvss 6.1epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() rejected raw BiDi formatting characters but not percent-encoded forms and used an ASCII-only whitespace check,…

  • CVE-2026-48747MedJul 14, 2026
    risk 0.27cvss 5.3epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::validateSignature() parsed X-MOM-Webhook-Signature as algo=signature and passed the request-selected algorithm to hash_hmac(),…

  • CVE-2026-48736HigJul 14, 2026
    risk 0.49cvss 8.6epss 0.01

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and IpUtils::PRIVATE_SUBNETS omitted IPv6 transition prefixes such as 6to4, NAT64, Teredo, and…

  • CVE-2026-48489HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.01

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, DefaultAuthenticationFailureHandler honored the request-supplied _failure_path parameter when failure_forward: true was enabled,…

  • CVE-2026-48371MedJul 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page…

  • CVE-2026-48359CriJul 14, 2026
    risk 0.62cvss 9.6epss 0.01

    Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to read sensitive…

  • CVE-2026-48358CriJul 14, 2026
    risk 0.59cvss 9.1epss 0.01

    Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of…

  • CVE-2026-48356CriJul 14, 2026
    risk 0.61cvss 9.3epss 0.01

    Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of…

  • CVE-2026-48355MedJul 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the…

  • CVE-2026-48350HigJul 14, 2026
    risk 0.56cvss 8.6epss 0.00

    Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to access sensitive files or…

  • CVE-2026-48349HigJul 14, 2026
    risk 0.53cvss 8.1epss 0.00

    Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is…

  • CVE-2026-48348HigJul 14, 2026
    risk 0.50cvss 7.7epss 0.00

    Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2026-48347HigJul 14, 2026
    risk 0.50cvss 7.7epss 0.01

    Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

  • CVE-2026-48346HigJul 14, 2026
    risk 0.51cvss 7.9epss 0.00

    Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

  • CVE-2026-48345HigJul 14, 2026
    risk 0.53cvss 8.2epss 0.01

    Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

  • CVE-2026-48310HigJul 14, 2026
    risk 0.56cvss 8.6epss 0.01

    Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside…

  • CVE-2026-48263MedJul 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the…

  • CVE-2026-48262MedJul 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires…

  • CVE-2026-48261MedJul 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires…

  • CVE-2026-48260MedJul 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires…

  • CVE-2026-48259CriJul 14, 2026
    risk 0.62cvss 9.6epss 0.01

    Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to issue unauthorized server-side requests,…

  • CVE-2026-48257MedJul 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires…

  • CVE-2026-48255MedJul 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires…

  • CVE-2026-48254MedJul 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires…

  • CVE-2026-48253MedJul 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires…

  • CVE-2026-48252HigJul 14, 2026
    risk 0.56cvss 8.6epss 0.01

    Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this…

  • CVE-2026-48069HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    @grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming compressed message can cause a client or server process that uses @grpc/grpc-js to crash. This…

  • CVE-2026-48068HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    @grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming HTTP/2 stream initiation can cause a server process created using @grpc/grpc-js to crash. This…

  • CVE-2026-48038MedJul 14, 2026
    risk 0.27cvss 5.3epss 0.01

    joi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1, denial of service is possible via an untrapped exception in services validating user-supplied JSON or object input with recursive link() schemas. When validate() is called…

  • CVE-2026-48001LowJul 14, 2026
    risk 0.24cvss 3.7epss 0.01

    Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited disclosure of sensitive information. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.

  • CVE-2026-48000MedJul 14, 2026
    risk 0.40cvss 6.1epss 0.00

    Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site. Exploitation of this issue requires user…

  • CVE-2026-47999MedJul 14, 2026
    risk 0.31cvss 4.8epss 0.00

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page…

  • CVE-2026-47998MedJul 14, 2026
    risk 0.38cvss 5.9epss 0.01

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's…

  • CVE-2026-47997MedJul 14, 2026
    risk 0.38cvss 5.9epss 0.01

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's…

  • CVE-2026-47996MedJul 14, 2026
    risk 0.44cvss 6.8epss 0.01

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. A high-privileged attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this…

  • CVE-2026-47995HigJul 14, 2026
    risk 0.53cvss 8.1epss 0.01

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page…

  • CVE-2026-47994HigJul 14, 2026
    risk 0.57cvss 8.7epss 0.01

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page…

  • CVE-2026-47992HigJul 14, 2026
    risk 0.47cvss 7.2epss 0.01

    Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to…

  • CVE-2026-47988HigJul 14, 2026
    risk 0.56cvss 8.6epss 0.01

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access, causing a limited disruption to…

  • CVE-2026-47984HigJul 14, 2026
    risk 0.53cvss 8.2epss 0.01

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does…

  • CVE-2026-47737HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.00

    Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vulnerable to source IP spoofing when set_remote_address proxy_protocol: :v1 is enabled and persistent connections are used because Puma incorrectly re-parses PROXY protocol headers…

  • CVE-2026-47736HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.00

    Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, when PROXY protocol v1 support is enabled, Puma reads incoming bytes into an internal buffer while waiting for CRLF to determine whether a PROXY v1 line is present, allowing an attacker that…

  • CVE-2026-47482HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory after effective lifetime. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2026-47481MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.00

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information…

  • CVE-2026-47480HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2026-47479HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.