2026 CVE Vulnerabilities
56,233 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21343 | HIGH | 7.8 | 0.2% | Feb 10, 2026 | Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a craft... |
| CVE-2026-21342 | HIGH | 7.8 | 0.2% | Feb 10, 2026 | Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result i... |
| CVE-2026-21341 | HIGH | 7.8 | 0.1% | Feb 10, 2026 | Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result i... |
| CVE-2026-1850 | HIGH | 7.5 | 0.2% | Feb 10, 2026 | Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash. |
| CVE-2026-1849 | HIGH | 7.5 | 0.3% | Feb 10, 2026 | MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents... |
| CVE-2026-1848 | HIGH | 8.2 | 0.3% | Feb 10, 2026 | Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes i... |
| CVE-2026-1847 | HIGH | 7.5 | 0.2% | Feb 10, 2026 | Inserting certain large documents into a replica set could lead to replica set secondaries not being able to fetch the o... |
| CVE-2026-25992 | HIGH | 7.5 | 0.5% | Feb 10, 2026 | SiYuan is a personal knowledge management system. Prior to 3.5.5, the /api/file/getFile endpoint uses case-sensitive str... |
| CVE-2026-25947 | HIGH | 8.8 | 0.4% | Feb 10, 2026 | Worklenz is a project management tool. Prior to 2.1.7, there are multiple SQL injection vulnerabilities were discovered ... |
| CVE-2026-25805 | HIGH | 8 | 0.2% | Feb 10, 2026 | Zed is a multiplayer code editor. Prior to 0.219.4, Zed does not show with which parameters a tool is being invoked, whe... |
| CVE-2026-25728 | HIGH | 7.5 | 0.3% | Feb 10, 2026 | ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #40, a Time-of-Check to Time-of-Use (TOCTOU) ra... |
| CVE-2026-25646 | HIGH | 8.1 | 1.0% | Feb 10, 2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2026-25612 | HIGH | 7.1 | 0.2% | Feb 10, 2026 | The internal locking mechanism of the MongoDB server uses an internal encoding of the resources in order to choose what ... |
| CVE-2026-25611 | HIGH | 8.7 | 0.8% | Feb 10, 2026 | A series of specifically crafted, unauthenticated messages can exhaust available memory and crash a MongoDB server. |
| CVE-2026-25577 | HIGH | 7.5 | 0.3% | Feb 10, 2026 | Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core... |
| CVE-2026-21537 | HIGH | 8.8 | 0.5% | Feb 10, 2026 | Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacke... |
| CVE-2026-21533 | HIGH | 7.8 | 3.8% | Feb 10, 2026 | Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. |
| CVE-2026-21523 | HIGH | 8 | 0.8% | Feb 10, 2026 | Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to e... |
| CVE-2026-21519 | HIGH | 7.8 | 2.4% | Feb 10, 2026 | Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to... |
| CVE-2026-21518 | HIGH | 8.8 | 1.4% | Feb 10, 2026 | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio ... |
| CVE-2026-21517 | HIGH | 7 | 0.4% | Feb 10, 2026 | Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to e... |
| CVE-2026-21516 | HIGH | 7.8 | 0.8% | Feb 10, 2026 | Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthor... |
| CVE-2026-21514 | HIGH | 7.8 | 1.5% | Feb 10, 2026 | Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a... |
| CVE-2026-21513 | HIGH | 8.8 | 15.4% | Feb 10, 2026 | Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a net... |
| CVE-2026-21511 | HIGH | 7.5 | 3.6% | Feb 10, 2026 | Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now