2026 CVE Vulnerabilities

69,558 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-27276HIGH7.8Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbi...
CVE-2026-27275HIGH7.8Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result i...
CVE-2026-27274HIGH7.8Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result i...
CVE-2026-27273HIGH7.8Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result i...
CVE-2026-27269HIGH7.8Premiere Pro versions 25.5 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, ...
CVE-2026-27219MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to...
CVE-2026-27218MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-27217MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-27216MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to...
CVE-2026-27215MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-27214MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-26801HIGH7.5Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker...
CVE-2026-26742HIGH8.1PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. ...
CVE-2026-26741HIGH8.1PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from A...
CVE-2026-21365MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to...
CVE-2026-21364MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-21363MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-3862MEDIUM4.8Cross-site Scripting (XSS) allows an attacker to submit specially crafted data to the application which is returned unal...
CVE-2026-3854HIGH8.8An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an ...
CVE-2026-3847HIGH8.8Memory safety bugs present in Firefox 148.0.2. Some of these bugs showed evidence of memory corruption and we presume th...
CVE-2026-3846MEDIUM6.5Same-origin policy bypass in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 148.0.2.
CVE-2026-3845HIGH8.8Heap buffer overflow in the Audio/Video: Playback component in Firefox for Android. This vulnerability was fixed in Fire...
CVE-2026-3843CRITICAL9.8Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-8...
CVE-2026-3483HIGH7.8An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate thei...
CVE-2026-3315HIGH7.8Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical R...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now