2026 CVE Vulnerabilities
53,348 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21348 | MEDIUM | 5.5 | 0.2% | Feb 10, 2026 | Substance3D - Modeler versions 1.22.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to... |
| CVE-2026-1763 | MEDIUM | 4.6 | 0.2% | Feb 10, 2026 | Vulnerability in GE Vernova Enervista UR Setup on Windows.This issue affects Enervista: 8.6 and previous versions. |
| CVE-2026-2302 | MEDIUM | 6.9 | 0.2% | Feb 10, 2026 | Under specific conditions when processing a maliciously crafted value of type Hash r, Mongoid::Criteria.from_hash may al... |
| CVE-2026-25609 | MEDIUM | 4.3 | 0.2% | Feb 10, 2026 | Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read... |
| CVE-2026-21355 | MEDIUM | 5.5 | 0.2% | Feb 10, 2026 | DNG SDK versions 1.7.1 2410 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory ex... |
| CVE-2026-21354 | MEDIUM | 5.5 | 0.1% | Feb 10, 2026 | DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead ... |
| CVE-2026-26003 | MEDIUM | 5.4 | 0.2% | Feb 10, 2026 | FastGPT is an AI Agent building platform. From 4.14.0 to 4.14.5, attackers can directly access the plugin system through... |
| CVE-2026-25956 | MEDIUM | 6.1 | 0.2% | Feb 10, 2026 | Frappe is a full-stack web application framework. Prior to 14.99.14 and 15.94.0, an attacker could craft a malicious sig... |
| CVE-2026-24045 | MEDIUM | 5.4 | 0.2% | Feb 10, 2026 | Docmost is open-source collaborative wiki and documentation software. From 0.20.0 and before 0.25.0, the public share pa... |
| CVE-2026-23655 | MEDIUM | 6.5 | 1.0% | Feb 10, 2026 | Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose informatio... |
| CVE-2026-21529 | MEDIUM | 5.4 | 0.6% | Feb 10, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an autho... |
| CVE-2026-21528 | MEDIUM | 6.5 | 0.5% | Feb 10, 2026 | Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over... |
| CVE-2026-21527 | MEDIUM | 6.5 | 9.5% | Feb 10, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attack... |
| CVE-2026-21525 | MEDIUM | 6.2 | 5.0% | Feb 10, 2026 | Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service loc... |
| CVE-2026-21522 | MEDIUM | 6.7 | 0.4% | Feb 10, 2026 | Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an a... |
| CVE-2026-21512 | MEDIUM | 6.5 | 1.0% | Feb 10, 2026 | Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a netwo... |
| CVE-2026-21358 | MEDIUM | 5.5 | 0.2% | Feb 10, 2026 | InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could... |
| CVE-2026-21350 | MEDIUM | 5.5 | 0.1% | Feb 10, 2026 | After Effects versions 25.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to appl... |
| CVE-2026-21340 | MEDIUM | 5.5 | 0.2% | Feb 10, 2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead t... |
| CVE-2026-21339 | MEDIUM | 5.5 | 0.2% | Feb 10, 2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead t... |
| CVE-2026-21338 | MEDIUM | 5.5 | 0.1% | Feb 10, 2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could l... |
| CVE-2026-21337 | MEDIUM | 5.5 | 0.2% | Feb 10, 2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by an Out-of-bounds Read vulnerability that could lead t... |
| CVE-2026-21336 | MEDIUM | 5.5 | 0.1% | Feb 10, 2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could l... |
| CVE-2026-21332 | MEDIUM | 5.5 | 0.2% | Feb 10, 2026 | InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead t... |
| CVE-2026-21319 | MEDIUM | 5.5 | 0.2% | Feb 10, 2026 | After Effects versions 25.6 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ex... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now