VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,947 CVE recordsPage 305 of 1264 · EPSS data 2026.08.02
ReviewCritical
CVE-2026-48322

Adobe ColdFusion 2025, ColdFusion 2023, coldfusion

ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-48321

Adobe ColdFusion 2025, ColdFusion 2023, coldfusion

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.

The CVSS severity warrants an early asset and exposure review.
PriorityHigh
CVE-2026-48320

Adobe ColdFusion 2025, ColdFusion 2023, coldfusion

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

FIRST EPSS indicates an elevated probability of exploitation.
PriorityCritical
CVE-2026-48319

Adobe ColdFusion 2025, ColdFusion 2023, coldfusion

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

FIRST EPSS indicates an elevated probability of exploitation.
PriorityCritical
CVE-2026-48318

Adobe ColdFusion 2025, ColdFusion 2023, coldfusion

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

FIRST EPSS indicates an elevated probability of exploitation.
ReviewHigh
CVE-2026-48311

Adobe Adobe Bridge, bridge, macos

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

The CVSS severity warrants an early asset and exposure review.
PriorityCritical
CVE-2026-48284

Adobe ColdFusion 2025, ColdFusion 2023, coldfusion

ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.

FIRST EPSS indicates an elevated probability of exploitation.
ReviewHigh
CVE-2026-48274

Adobe After Effects, after effects

After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48272

Adobe Creative Cloud Desktop, creative cloud desktop application, windows

Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48270

Adobe Premiere, premiere pro

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48269

Adobe Premiere, premiere pro

Premiere Pro is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47976

Adobe Adobe Media Encoder, media encoder

Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47971

Adobe Adobe Media Encoder, media encoder

Media Encoder is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47473

NVIDIA TensorRT-LLM

NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47472

NVIDIA TensorRT-LLM

NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, and denial of service.

The CVSS severity warrants an early asset and exposure review.