CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2026-21322

    Last Modified: 18 Apr 2026

    After Effects versions 25.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Feb 2026
    7.8
    High

    CVE-2026-21318

    Last Modified: 18 Apr 2026

    After Effects versions 25.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Feb 2026
    7.8
    High

    CVE-2026-21328

    Last Modified: 17 Apr 2026

    After Effects versions 25.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Feb 2026
    5.5
    Medium

    CVE-2026-21319

    Last Modified: 18 Apr 2026

    After Effects versions 25.6 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Feb 2026
    5.5
    Medium

    CVE-2026-21350

    Last Modified: 18 Apr 2026

    After Effects versions 25.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Feb 2026
    7.8
    High

    CVE-2026-21330

    Last Modified: 17 Apr 2026

    After Effects versions 25.6 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Feb 2026
    7.8
    High

    CVE-2026-21325

    Last Modified: 17 Apr 2026

    After Effects versions 25.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Feb 2026
    7.8
    High

    CVE-2026-21327

    Last Modified: 17 Apr 2026

    After Effects versions 25.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Feb 2026
    7.8
    High

    CVE-2026-21320

    Last Modified: 17 Apr 2026

    After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Feb 2026
    7.8
    High

    CVE-2026-21321

    Last Modified: 18 Apr 2026

    After Effects versions 25.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Feb 2026
    7.8
    High

    CVE-2026-21351

    Last Modified: 17 Apr 2026

    After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Feb 2026
    8.7
    High

    CVE-2026-25611

    Last Modified: 18 Apr 2026

    A series of specifically crafted, unauthenticated messages can exhaust available memory and crash a MongoDB server.

    Published: 10 Feb 2026
    6.9
    Medium

    CVE-2026-26003

    Last Modified: 17 Apr 2026

    FastGPT is an AI Agent building platform. From 4.14.0 to 4.14.5, attackers can directly access the plugin system through FastGPT/api/plugin/xxx without authentication, thereby threatening the plugin system. This may cause the plugin system to crash and the loss of plugin installation status, but it will not result in key leakage. For older versions, as there are only operation interfaces for obtaining information, the impact is almost negligible. This vulnerability is fixed in 4.14.5-fix.

    Published: 10 Feb 2026
    7.8
    High

    CVE-2026-20841

    Last Modified: 15 Apr 2026

    Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.

    Published: 10 Feb 2026
    7.5
    High

    CVE-2026-20846

    Last Modified: 19 Aug 2026

    Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.

    Published: 10 Feb 2026
    5.5
    Medium

    CVE-2026-21222

    Last Modified: 15 Apr 2026

    Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

    Published: 10 Feb 2026
    8.1
    High

    CVE-2026-21228

    Last Modified: 15 Apr 2026

    Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network.

    Published: 10 Feb 2026
    7.8
    High

    CVE-2026-21231

    Last Modified: 15 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 10 Feb 2026
    7.8
    High

    CVE-2026-21232

    Last Modified: 15 Apr 2026

    Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

    Published: 10 Feb 2026
    7
    High

    CVE-2026-21237

    Last Modified: 15 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

    Published: 10 Feb 2026
    7.8
    High

    CVE-2026-21238

    Last Modified: 15 Apr 2026

    Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 10 Feb 2026
    7.8
    High

    CVE-2026-21239

    Last Modified: 15 Apr 2026

    Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 10 Feb 2026
    7
    High

    CVE-2026-21241

    Last Modified: 15 Apr 2026

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 10 Feb 2026
    7.8
    High

    CVE-2026-21240

    Last Modified: 15 Apr 2026

    Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

    Published: 10 Feb 2026
    7.5
    High

    CVE-2026-21243

    Last Modified: 15 Apr 2026

    Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

    Published: 10 Feb 2026
    7.3
    High

    CVE-2026-21244

    Last Modified: 15 Apr 2026

    Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

    Published: 10 Feb 2026
    7.8
    High

    CVE-2026-21245

    Last Modified: 15 Apr 2026

    Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 10 Feb 2026
    3.3
    Low

    CVE-2026-21249

    Last Modified: 15 Apr 2026

    External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.

    Published: 10 Feb 2026
    7.8
    High

    CVE-2026-21250

    Last Modified: 15 Apr 2026

    Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

    Published: 10 Feb 2026
    7.8
    High

    CVE-2026-21251

    Last Modified: 15 Apr 2026

    Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally.

    Published: 10 Feb 2026
    7
    High

    CVE-2026-21253

    Last Modified: 15 Apr 2026

    Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.

    Published: 10 Feb 2026
    8.8
    High

    CVE-2026-21255

    Last Modified: 15 Apr 2026

    Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.

    Published: 10 Feb 2026
    8.8
    High

    CVE-2026-21256

    Last Modified: 15 Apr 2026

    Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network.

    Published: 10 Feb 2026
    8
    High

    CVE-2026-21257

    Last Modified: 15 Apr 2026

    Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker to elevate privileges over a network.

    Published: 10 Feb 2026
    5.5
    Medium

    CVE-2026-21261

    Last Modified: 15 Apr 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

    Published: 10 Feb 2026
    7
    High

    CVE-2026-21508

    Last Modified: 15 Apr 2026

    Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.

    Published: 10 Feb 2026
    7.5
    High

    CVE-2026-21511

    Last Modified: 15 Apr 2026

    Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

    Published: 10 Feb 2026
    8.8
    High

    CVE-2026-21516

    Last Modified: 15 Apr 2026

    Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network.

    Published: 10 Feb 2026
    6.2
    Medium

    CVE-2026-21525

    Last Modified: 22 Apr 2026

    Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

    Published: 10 Feb 2026
    7.8
    High

    CVE-2026-21514

    Last Modified: 15 Apr 2026

    Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

    Published: 10 Feb 2026
    5.7
    Medium

    CVE-2026-21529

    Last Modified: 15 Apr 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network.

    Published: 10 Feb 2026
    8.8
    High

    CVE-2026-21537

    Last Modified: 15 Apr 2026

    Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network.

    Published: 10 Feb 2026
    8.8
    High

    CVE-2026-21510

    Last Modified: 15 Apr 2026

    Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

    Published: 10 Feb 2026
    9.8
    Critical

    CVE-2026-21531

    Last Modified: 15 Apr 2026

    Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.

    Published: 10 Feb 2026
    6.5
    Medium

    CVE-2026-21528

    Last Modified: 15 Apr 2026

    Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

    Published: 10 Feb 2026
    6.5
    Medium

    CVE-2026-21527

    Last Modified: 15 Jun 2026

    User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

    Published: 10 Feb 2026
    6.7
    Medium

    CVE-2026-21522

    Last Modified: 15 Apr 2026

    Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

    Published: 10 Feb 2026
    8.8
    High

    CVE-2026-21513

    Last Modified: 22 Apr 2026

    Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

    Published: 10 Feb 2026
    7.8
    High

    CVE-2026-21533

    Last Modified: 22 Apr 2026

    Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

    Published: 10 Feb 2026
    8
    High

    CVE-2026-21229

    Last Modified: 16 Apr 2026

    Improper input validation in Power BI allows an authorized attacker to execute code over a network.

    Published: 10 Feb 2026