Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVSS Score
7.0
EPSS Score
0.002
Published
2026-07-14
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVSS Score
7.5
EPSS Score
0.008
Published
2026-07-14
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVSS Score
8.2
EPSS Score
0.006
Published
2026-07-14
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVSS Score
7.8
EPSS Score
0.009
Published
2026-07-14
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVSS Score
7.5
EPSS Score
0.008
Published
2026-07-14
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::validateSignature() parsed X-MOM-Webhook-Signature as algo=signature and passed the request-selected algorithm to hash_hmac(), allowing a signature algorithm downgrade instead of enforcing Mailomat's documented SHA-256 webhook signature. This issue is fixed in versions 7.4.13 and 8.0.13.
CVSS Score
6.3
EPSS Score
0.002
Published
2026-07-14
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() rejected raw BiDi formatting characters but not percent-encoded forms and used an ASCII-only whitespace check, allowing sanitized URLs to retain visual-spoofing characters that downstream consumers could decode or display. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.
CVSS Score
5.3
EPSS Score
0.003
Published
2026-07-14
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() omitted URL-bearing attributes on <object>, <applet>, <iframe>, and <img>, and <meta http-equiv="refresh"> URLs inside content bypassed URL sanitization, allowing explicitly enabled elements or attributes to pass javascript: and similar payloads into sanitized output. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.
CVSS Score
5.3
EPSS Score
0.003
Published
2026-07-14
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr() dot-segment encoding that skipped every other chained ../ or ./ segment, allowing attacker-controlled route parameters to generate URLs that collapse to a different path under RFC 3986 normalization. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.
CVSS Score
5.1
EPSS Score
0.003
Published
2026-07-14
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
CVSS Score
5.4
EPSS Score
0.002
Published
2026-07-14


Contact Us

Shodan ® - All rights reserved