Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
50,097 matching · page 451/1002Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-25506(opens NVD record) | High | 7.7 | MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18. | Feb 10, 2026 |
| CVE-2026-21347(opens NVD record) | High | 7.8 | Bridge versions 15.1.3, 16.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21346(opens NVD record) | High | 7.8 | Bridge versions 15.1.3, 16.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21345(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21344(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21343(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21342(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21341(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-25646(opens NVD record) | High | 8.1 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user's display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55. | Feb 10, 2026 |
| CVE-2026-23655(opens NVD record) | Medium | 6.5 | Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose information over a network. | Feb 10, 2026 |
| CVE-2026-21537(opens NVD record) | High | 8.8 | Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network. | Feb 10, 2026 |
| CVE-2026-21533(opens NVD record) | High | 7.8 | Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. | Feb 10, 2026 |
| CVE-2026-21531(opens NVD record) | Critical | 9.8 | Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network. | Feb 10, 2026 |
| CVE-2026-21529(opens NVD record) | Medium | 5.7 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network. | Feb 10, 2026 |
| CVE-2026-21528(opens NVD record) | Medium | 6.5 | Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | Feb 10, 2026 |
| CVE-2026-21527(opens NVD record) | Medium | 6.5 | User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | Feb 10, 2026 |
| CVE-2026-21525(opens NVD record) | Medium | 6.2 | Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally. | Feb 10, 2026 |
| CVE-2026-21523(opens NVD record) | High | 8.0 | Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network. | Feb 10, 2026 |
| CVE-2026-21522(opens NVD record) | Medium | 6.7 | Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. | Feb 10, 2026 |
| CVE-2026-21519(opens NVD record) | High | 7.8 | Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | Feb 10, 2026 |
| CVE-2026-21518(opens NVD record) | High | 8.8 | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | Feb 10, 2026 |
| CVE-2026-21517(opens NVD record) | Medium | 4.7 | Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally. | Feb 10, 2026 |
| CVE-2026-21516(opens NVD record) | High | 8.8 | Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network. | Feb 10, 2026 |
| CVE-2026-21514(opens NVD record) | High | 7.8 | Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally. | Feb 10, 2026 |
| CVE-2026-21513(opens NVD record) | High | 8.8 | Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. | Feb 10, 2026 |
| CVE-2026-21512(opens NVD record) | Medium | 6.5 | Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network. | Feb 10, 2026 |
| CVE-2026-21511(opens NVD record) | High | 7.5 | Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | Feb 10, 2026 |
| CVE-2026-21510(opens NVD record) | High | 8.8 | Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. | Feb 10, 2026 |
| CVE-2026-21508(opens NVD record) | High | 7.0 | Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally. | Feb 10, 2026 |
| CVE-2026-21358(opens NVD record) | Medium | 5.5 | InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21357(opens NVD record) | High | 7.8 | InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21351(opens NVD record) | High | 7.8 | After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21350(opens NVD record) | Medium | 5.5 | After Effects versions 25.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21332(opens NVD record) | Medium | 5.5 | InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21330(opens NVD record) | High | 7.8 | After Effects versions 25.6 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21329(opens NVD record) | High | 7.8 | After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21328(opens NVD record) | High | 7.8 | After Effects versions 25.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21327(opens NVD record) | High | 7.8 | After Effects versions 25.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21326(opens NVD record) | High | 7.8 | After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21325(opens NVD record) | High | 7.8 | After Effects versions 25.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21324(opens NVD record) | High | 7.8 | After Effects versions 25.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21323(opens NVD record) | High | 7.8 | After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21322(opens NVD record) | High | 7.8 | After Effects versions 25.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21321(opens NVD record) | High | 7.8 | After Effects versions 25.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21320(opens NVD record) | High | 7.8 | After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21319(opens NVD record) | Medium | 5.5 | After Effects versions 25.6 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21318(opens NVD record) | High | 7.8 | After Effects versions 25.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Feb 10, 2026 |
| CVE-2026-21261(opens NVD record) | Medium | 5.5 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | Feb 10, 2026 |
| CVE-2026-21260(opens NVD record) | High | 7.5 | Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | Feb 10, 2026 |
| CVE-2026-21259(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally. | Feb 10, 2026 |