2026 CVE Vulnerabilities

53,348 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-21348MEDIUM5.5Substance3D - Modeler versions 1.22.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to...
CVE-2026-1763MEDIUM4.6Vulnerability in GE Vernova Enervista UR Setup on Windows.This issue affects Enervista: 8.6 and previous versions.
CVE-2026-2302MEDIUM6.9Under specific conditions when processing a maliciously crafted value of type Hash r, Mongoid::Criteria.from_hash may al...
CVE-2026-25609MEDIUM4.3Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read...
CVE-2026-21355MEDIUM5.5DNG SDK versions 1.7.1 2410 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory ex...
CVE-2026-21354MEDIUM5.5DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead ...
CVE-2026-26003MEDIUM5.4FastGPT is an AI Agent building platform. From 4.14.0 to 4.14.5, attackers can directly access the plugin system through...
CVE-2026-25956MEDIUM6.1Frappe is a full-stack web application framework. Prior to 14.99.14 and 15.94.0, an attacker could craft a malicious sig...
CVE-2026-24045MEDIUM5.4Docmost is open-source collaborative wiki and documentation software. From 0.20.0 and before 0.25.0, the public share pa...
CVE-2026-23655MEDIUM6.5Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose informatio...
CVE-2026-21529MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an autho...
CVE-2026-21528MEDIUM6.5Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over...
CVE-2026-21527MEDIUM6.5User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attack...
CVE-2026-21525MEDIUM6.2Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service loc...
CVE-2026-21522MEDIUM6.7Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an a...
CVE-2026-21512MEDIUM6.5Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a netwo...
CVE-2026-21358MEDIUM5.5InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could...
CVE-2026-21350MEDIUM5.5After Effects versions 25.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to appl...
CVE-2026-21340MEDIUM5.5Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead t...
CVE-2026-21339MEDIUM5.5Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead t...
CVE-2026-21338MEDIUM5.5Substance3D - Designer versions 15.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could l...
CVE-2026-21337MEDIUM5.5Substance3D - Designer versions 15.1.0 and earlier are affected by an Out-of-bounds Read vulnerability that could lead t...
CVE-2026-21336MEDIUM5.5Substance3D - Designer versions 15.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could l...
CVE-2026-21332MEDIUM5.5InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead t...
CVE-2026-21319MEDIUM5.5After Effects versions 25.6 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ex...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now