Every CVE of the last six months, updated daily.
Published vulnerabilities straight from the National Vulnerability Database, with severity, CWE class and affected products. Search it, filter it, and see what landed today.
- 257 published in the last 24 hours
- 2,764 in the last 7 days
- 58,275 in the last six months
Source: NVD (National Vulnerability Database) · Updated Sep 23, 2026
Showing 2 of 2
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() rejected raw BiDi formatting characters but not percent-encoded forms and used an ASCII-only wh
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlSanitizer::parse() passes Unicode explicit-direction BiDi formatting characters through into sanitized href
Find the bug before an attacker does.
Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.