cve
Vulnerability watch Full archive
idvulnerabilityseveritypublished
CVE-2026-48347Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.Adobe Animate High CVSS 7.7 CVE-2026-48348Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.Adobe Animate High CVSS 7.7 CVE-2026-48349Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.Adobe Animate High CVSS 8.1 CVE-2026-48350Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to access sensitive files or directories outside the intended restrictions. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.Adobe Animate High CVSS 8.6 CVE-2026-48351CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.Adobe C2pa High CVSS 7.5 CVE-2026-48352CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.Adobe C2pa High CVSS 7.5 CVE-2026-48356Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.Adobe Commerce Critical CVSS 9.3 CVE-2026-48358Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.Adobe Commerce Critical CVSS 10 CVE-2026-48359Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to read sensitive files, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.Adobe Experience Manager Critical CVSS 9.6 CVE-2026-48365Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Adobe Audition High CVSS 7.8 CVE-2026-48366Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Adobe Media Encoder High CVSS 7.8 CVE-2026-48367After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Adobe After Effects High CVSS 7.8 CVE-2026-48368Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Adobe Audition High CVSS 7.8 CVE-2026-48369Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Adobe Premiere Pro High CVSS 7.8 CVE-2026-48370Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Adobe Media Encoder High CVSS 7.8 CVE-2026-48489Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, DefaultAuthenticationFailureHandler honored the request-supplied _failure_path parameter when failure_forward: true was enabled, allowing an unauthenticated failing login request to dispatch a subrequest to access_control-protected GET routes that skipped firewall listeners. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.Sensiolabs Symfony High CVSS 7.5 CVE-2026-48561Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.Microsoft 365 Copilot Critical CVSS 9.6 CVE-2026-48564Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.8 CVE-2026-48571Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 23h2 High CVSS 7 CVE-2026-48572Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 23h2 High CVSS 7 CVE-2026-48581Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.Microsoft Surface Go 2 1901 Firmware High CVSS 7.8 CVE-2026-48736Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and IpUtils::PRIVATE_SUBNETS omitted IPv6 transition prefixes such as 6to4, NAT64, Teredo, and IPv4-compatible IPv6, allowing attacker-supplied URLs to represent private IPv4 targets in forms that IpUtils::isPrivateIp() did not block. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.Sensiolabs Symfony High CVSS 8.6 CVE-2026-48801linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails. Any service that synchronously renders untrusted Markdown with linkify:true on a request hot path can inherit a worker-process denial of service triggerable by a tens-of-KB request body. This issue is fixed in version 5.0.1.NVD analysis in progress High CVSS 8.7 CVE-2026-48805Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(), allowing legacy calls such as twig_array_some(), twig_array_every(), and twig_check_arrow_in_sandbox() to bypass sandbox callable restrictions. This issue is fixed in version 3.27.0.Symfony Twig Critical CVSS 9.1 CVE-2026-48806Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key without calling SandboxExtension::ensureToStringAllowed(). This issue is fixed in version 3.27.0.Symfony Twig Critical CVSS 9.1 CVE-2026-48807Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0.Symfony Twig Critical CVSS 9.1 CVE-2026-48808Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are lost and a template author can read public or magic properties not allowed by the sandbox policy. This issue is fixed in version 3.27.0.Symfony Twig High CVSS 7.5 CVE-2026-48815sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked and applications relying on certificateOIDs to restrict which certificates may sign artifacts can accept unauthorized certificates. This issue is fixed in version 4.1.1. High CVSS 7.5 CVE-2026-49162Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-49164Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critical CVSS 9.8 CVE-2026-49165Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.Microsoft Windows 10 1607 High CVSS 7.1 CVE-2026-49166Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-49167Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-49169Use after free in DNS Server allows an authorized attacker to execute code over a network.Microsoft Windows Server 2025 High CVSS 8.8 CVE-2026-49170Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-49171Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-49172Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critical CVSS 9.8 CVE-2026-49173Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 26h1 High CVSS 7.8 CVE-2026-49175Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 High CVSS 7.8 CVE-2026-49176Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-49178Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.8 CVE-2026-49181Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 Critical CVSS 9.8 CVE-2026-49183Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7 CVE-2026-49184Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-49476Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.NVD analysis in progress High CVSS 7.5 CVE-2026-49477Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in soupsieve/css_parser.py, allowing an attacker who can supply untrusted CSS selector strings to soupsieve.compile() or Beautiful Soup .select() / .select_one() to cause CPU exhaustion and denial of service. This issue is fixed in version 2.8.4.NVD analysis in progress High CVSS 7.5 CVE-2026-49783Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-49784Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-49787Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-49788Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-49789Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-49790Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege VulnerabilityMicrosoft Windows 10 1607 High CVSS 7.8 CVE-2026-49791Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-49792Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-49793Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-49795Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 8.8 CVE-2026-49796Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-49797Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-49798Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Critical CVSS 9.3 CVE-2026-49800Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-49802Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-49803Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-49805Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-49806Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-49808Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-49853Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6. High CVSS 7.7 CVE-2026-49855Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6. High CVSS 7.5 CVE-2026-49981Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allowing a later sandboxed render to reuse a template that was originally checked with a different or empty policy. This issue is fixed in version 3.27.0.Symfony Twig High CVSS 8.2 CVE-2026-50130Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by replacing /etc/pihole/logrotate. The replacement is laundered to root:root ownership by pihole-FTL-prestart.sh and then parsed as root by the daily pihole flush cron, executing firstaction shell as uid 0. This issue is fixed in version 6.4.3.NVD analysis in progress High CVSS 8.8 CVE-2026-50293Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 High CVSS 7.8 CVE-2026-50296Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-50297Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-50301Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-50304Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-50305Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50306Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50307Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50308Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50309Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50311Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50312Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50313Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50314Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-50315Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50317Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-50318Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50321Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-50322Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-50323Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-50325Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-50326Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 High CVSS 7.8 CVE-2026-50327Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50328Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-50329Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50330Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 Critical CVSS 9.8 CVE-2026-50331Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50332Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50333Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50335Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50336Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 2701–2800 / 5155 CVE