2026 CVE Vulnerabilities
56,405 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0532 | HIGH | 8.6 | 0.4% | Jan 14, 2026 | External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker... |
| CVE-2026-22870 | HIGH | 7.5 | 0.4% | Jan 13, 2026 | GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, GuardDog's safe_extract() function does not ... |
| CVE-2026-22868 | HIGH | 7.5 | 0.6% | Jan 13, 2026 | go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced ... |
| CVE-2026-22862 | HIGH | 7.5 | 0.6% | Jan 13, 2026 | go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced ... |
| CVE-2026-22861 | HIGH | 8.8 | 0.6% | Jan 13, 2026 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio... |
| CVE-2026-21299 | HIGH | 7.8 | 0.2% | Jan 13, 2026 | Substance3D - Modeler versions 1.22.4 and earlier are affected by an out-of-bounds write vulnerability that could result... |
| CVE-2026-21298 | HIGH | 7.8 | 0.2% | Jan 13, 2026 | Substance3D - Modeler versions 1.22.4 and earlier are affected by an out-of-bounds write vulnerability that could result... |
| CVE-2026-0528 | HIGH | 7.5 | 0.3% | Jan 13, 2026 | Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service thr... |
| CVE-2026-22814 | HIGH | 8.2 | 0.5% | Jan 13, 2026 | @adonisjs/lucid is an SQL ORM for AdonisJS built on top of Knex. Prior to 21.8.2 and 22.0.0-next.6, there is a Mass Assi... |
| CVE-2026-21307 | HIGH | 7.8 | 0.2% | Jan 13, 2026 | Substance3D - Designer versions 15.0.3 and earlier are affected by an out-of-bounds write vulnerability that could resul... |
| CVE-2026-21306 | HIGH | 7.8 | 0.2% | Jan 13, 2026 | Substance3D - Sampler versions 5.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result ... |
| CVE-2026-21305 | HIGH | 7.8 | 0.2% | Jan 13, 2026 | Substance3D - Painter versions 11.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result... |
| CVE-2026-21287 | HIGH | 7.8 | 0.2% | Jan 13, 2026 | Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbi... |
| CVE-2026-21304 | HIGH | 7.8 | 0.2% | Jan 13, 2026 | InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could... |
| CVE-2026-21283 | HIGH | 7.8 | 0.3% | Jan 13, 2026 | Bridge versions 15.1.2, 16.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in... |
| CVE-2026-21281 | HIGH | 7.8 | 0.2% | Jan 13, 2026 | InCopy versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in... |
| CVE-2026-21280 | HIGH | 8.6 | 0.2% | Jan 13, 2026 | Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result i... |
| CVE-2026-21277 | HIGH | 7.8 | 0.2% | Jan 13, 2026 | InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could... |
| CVE-2026-21276 | HIGH | 7.8 | 0.2% | Jan 13, 2026 | InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that... |
| CVE-2026-21275 | HIGH | 7.8 | 0.2% | Jan 13, 2026 | InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that... |
| CVE-2026-21274 | HIGH | 7.8 | 0.2% | Jan 13, 2026 | Dreamweaver Desktop versions 21.6 and earlier are affected by an Incorrect Authorization vulnerability that could result... |
| CVE-2026-21272 | HIGH | 8.6 | 0.2% | Jan 13, 2026 | Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could lead... |
| CVE-2026-21271 | HIGH | 8.6 | 0.2% | Jan 13, 2026 | Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could resu... |
| CVE-2026-21268 | HIGH | 8.6 | 0.2% | Jan 13, 2026 | Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could resu... |
| CVE-2026-21267 | HIGH | 8.6 | 0.7% | Jan 13, 2026 | Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now