2026 CVE Vulnerabilities

56,233 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-21343HIGH7.8Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a craft...
CVE-2026-21342HIGH7.8Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result i...
CVE-2026-21341HIGH7.8Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result i...
CVE-2026-1850HIGH7.5Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash.
CVE-2026-1849HIGH7.5MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents...
CVE-2026-1848HIGH8.2Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes i...
CVE-2026-1847HIGH7.5Inserting certain large documents into a replica set could lead to replica set secondaries not being able to fetch the o...
CVE-2026-25992HIGH7.5SiYuan is a personal knowledge management system. Prior to 3.5.5, the /api/file/getFile endpoint uses case-sensitive str...
CVE-2026-25947HIGH8.8Worklenz is a project management tool. Prior to 2.1.7, there are multiple SQL injection vulnerabilities were discovered ...
CVE-2026-25805HIGH8Zed is a multiplayer code editor. Prior to 0.219.4, Zed does not show with which parameters a tool is being invoked, whe...
CVE-2026-25728HIGH7.5ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #40, a Time-of-Check to Time-of-Use (TOCTOU) ra...
CVE-2026-25646HIGH8.1LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2026-25612HIGH7.1The internal locking mechanism of the MongoDB server uses an internal encoding of the resources in order to choose what ...
CVE-2026-25611HIGH8.7A series of specifically crafted, unauthenticated messages can exhaust available memory and crash a MongoDB server.
CVE-2026-25577HIGH7.5Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core...
CVE-2026-21537HIGH8.8Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacke...
CVE-2026-21533HIGH7.8Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
CVE-2026-21523HIGH8Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to e...
CVE-2026-21519HIGH7.8Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to...
CVE-2026-21518HIGH8.8Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio ...
CVE-2026-21517HIGH7Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to e...
CVE-2026-21516HIGH7.8Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthor...
CVE-2026-21514HIGH7.8Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a...
CVE-2026-21513HIGH8.8Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a net...
CVE-2026-21511HIGH7.5Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now