CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2026-0921

    Last Modified: 2 Feb 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 13 Jan 2026
    8.2
    High

    CVE-2025-37168

    Last Modified: 23 Jan 2026

    Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 operating system. Successful exploitation of this vulnerability could allow an unauthenticated remote malicious actor to delete arbitrary files within the affected system and potentially result in denial-of-service conditions on affected devices.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-21306

    Last Modified: 18 Apr 2026

    Substance3D - Sampler versions 5.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2026
    8.2
    High

    CVE-2026-22817

    Last Modified: 18 Apr 2026

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the JWT header’s alg value to influence signature verification when the selected JWK did not explicitly specify an algorithm. This could enable JWT algorithm confusion and, in certain configurations, allow forged tokens to be accepted. As part of this fix, the JWT middleware now requires the alg option to be explicitly specified. This prevents algorithm confusion by ensuring that the verification algorithm is not derived from untrusted JWT header values. This vulnerability is fixed in 4.11.4.

    Published: 13 Jan 2026
    8.2
    High

    CVE-2026-22818

    Last Modified: 18 Apr 2026

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the algorithm specified in the JWT header to influence signature verification when the selected JWK did not explicitly define an algorithm. This could enable JWT algorithm confusion and, in certain configurations, allow forged tokens to be accepted. The JWK/JWKS JWT verification middleware has been updated to require an explicit allowlist of asymmetric algorithms when verifying tokens. The middleware no longer derives the verification algorithm from untrusted JWT header values. This vulnerability is fixed in 4.11.4.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-21287

    Last Modified: 18 Apr 2026

    Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2026
    8.2
    High

    CVE-2026-22814

    Last Modified: 18 Apr 2026

    @adonisjs/lucid is an SQL ORM for AdonisJS built on top of Knex. Prior to 21.8.2 and 22.0.0-next.6, there is a Mass Assignment vulnerability in AdonisJS Lucid which may allow a remote attacker who can influence data that is passed into Lucid model assignments to overwrite the internal ORM state. This may lead to logic bypasses and unauthorized record modification within a table or model. This affects @adonisjs/lucid through version 21.8.1 and 22.x pre-release versions prior to 22.0.0-next.6. This has been patched in @adonisjs/lucid versions 21.8.2 and 22.0.0-next.6.

    Published: 13 Jan 2026
    4.4
    Medium

    CVE-2026-22809

    Last Modified: 18 Apr 2026

    tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.29.0, a Regular Expression Denial of Service (ReDoS) vulnerability was identified in tarteaucitron.js in the handling of the issuu_id parameter. This vulnerability is fixed in 1.29.0.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-21305

    Last Modified: 18 Apr 2026

    Substance3D - Painter versions 11.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2026
    6.9
    Medium

    CVE-2025-68925

    Last Modified: 20 Jan 2026

    Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the code doesn't validate that the JWT header specifies "alg":"RS256". This vulnerability is fixed in 2.2.

    Published: 13 Jan 2026
    8.2
    High

    CVE-2025-68704

    Last Modified: 20 Jan 2026

    Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.util.Random() which is not cryptographically secure for timing attack mitigation. This vulnerability is fixed in 2.2.

    Published: 13 Jan 2026
    8.7
    High

    CVE-2025-68703

    Last Modified: 20 Jan 2026

    Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the salt is derived from sha256Sum(passphrase). Two encryption operations with the same password will have the same derived key. This vulnerability is fixed in 2.2.

    Published: 13 Jan 2026
    8.7
    High

    CVE-2025-68702

    Last Modified: 20 Jan 2026

    Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses padLeft(32, '0') when it should use padLeft(64, '0') because SHA-256 produces 32 bytes which equates to 64 hex characters. This vulnerability is fixed in 2.2.

    Published: 13 Jan 2026
    8.7
    High

    CVE-2025-68701

    Last Modified: 20 Jan 2026

    Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses deterministic AES IV derivation from a passphrase. This vulnerability is fixed in 2.2.

    Published: 13 Jan 2026
    8.7
    High

    CVE-2025-68931

    Last Modified: 20 Jan 2026

    Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding lacks authentication, making it vulnerable to padding oracle attacks and ciphertext manipulation. This vulnerability is fixed in 2.2.

    Published: 13 Jan 2026
    8.7
    High

    CVE-2025-68698

    Last Modified: 20 Jan 2026

    Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses PKCS1Encoding which is vulnerable to Bleichenbacher padding oracle attacks. Modern systems should use OAEP (Optimal Asymmetric Encryption Padding). This vulnerability is fixed in 2.2.

    Published: 13 Jan 2026
    6.6
    Medium

    CVE-2026-22791

    Last Modified: 18 Apr 2026

    openCryptoki is a PKCS#11 library and tools for Linux and AIX. In 3.25.0 and 3.26.0, there is a heap buffer overflow vulnerability in the CKM_ECDH_AES_KEY_WRAP implementation allows an attacker with local access to cause out-of-bounds writes in the host process by supplying a compressed EC public key and invoking C_WrapKey. This can lead to heap corruption, or denial-of-service.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-21283

    Last Modified: 18 Apr 2026

    Bridge versions 15.1.2, 16.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-21281

    Last Modified: 18 Apr 2026

    InCopy versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2026
    5.3
    Medium

    CVE-2025-68949

    Last Modified: 16 Jan 2026

    n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validation performed partial string matching instead of exact IP comparison. As a result, an incoming request could be accepted if the source IP address merely contained the configured whitelist entry as a substring. This issue affected instances where workflow editors relied on IP-based access controls to restrict webhook access. Both IPv4 and IPv6 addresses were impacted. An attacker with a non-whitelisted IP could bypass restrictions if their IP shared a partial prefix with a trusted address, undermining the intended security boundary. This vulnerability is fixed in 2.2.0.

    Published: 13 Jan 2026
    8.6
    High

    CVE-2026-21280

    Last Modified: 18 Apr 2026

    Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses a search path to locate critical resources such as programs, an attacker could modify that search path to point to a malicious program, which the targeted application would then execute. Exploitation of this issue requires user interaction in that a victim must open a malicious file and scope is changed.

    Published: 13 Jan 2026
    5.5
    Medium

    CVE-2026-21288

    Last Modified: 18 Apr 2026

    Illustrator versions 29.8.3, 30.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-21277

    Last Modified: 18 Apr 2026

    InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-21304

    Last Modified: 18 Apr 2026

    InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-21275

    Last Modified: 18 Apr 2026

    InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2026
    5.5
    Medium

    CVE-2026-21278

    Last Modified: 18 Apr 2026

    InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-21276

    Last Modified: 18 Apr 2026

    InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2026
    10
    Critical

    CVE-2025-68271

    Last Modified: 15 Apr 2026

    OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.0 to 6.10.1, OpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). This vulnerability is fixed in 6.10.2.

    Published: 13 Jan 2026
    8.6
    High

    CVE-2026-21267

    Last Modified: 18 Apr 2026

    Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue requires user interaction in that a victim must open a malicious file and scope is changed.

    Published: 13 Jan 2026
    8.6
    High

    CVE-2026-21271

    Last Modified: 18 Apr 2026

    Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file and scope is changed.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-21274

    Last Modified: 18 Apr 2026

    Dreamweaver Desktop versions 21.6 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could leverage this vulnerability to bypass security measures and execute unauthorized code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2026
    8.6
    High

    CVE-2026-21272

    Last Modified: 18 Apr 2026

    Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An attacker could leverage this vulnerability to manipulate or inject malicious data into files on the system. Exploitation of this issue requires user interaction in that a victim must open a malicious file and scope is changed.

    Published: 13 Jan 2026
    8.6
    High

    CVE-2026-21268

    Last Modified: 18 Apr 2026

    Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file and scope is changed.

    Published: 13 Jan 2026
    7.5
    High

    CVE-2026-21226

    Last Modified: 16 Apr 2026

    Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20941

    Last Modified: 16 Apr 2026

    Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    5.4
    Medium

    CVE-2026-20958

    Last Modified: 16 Apr 2026

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20957

    Last Modified: 16 Apr 2026

    Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 13 Jan 2026
    8.4
    High

    CVE-2026-20952

    Last Modified: 16 Apr 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20950

    Last Modified: 16 Apr 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20949

    Last Modified: 16 Apr 2026

    Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20948

    Last Modified: 18 Apr 2026

    Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 13 Jan 2026
    5.5
    Medium

    CVE-2026-20939

    Last Modified: 16 Apr 2026

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

    Published: 13 Jan 2026
    5.5
    Medium

    CVE-2026-20937

    Last Modified: 16 Apr 2026

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

    Published: 13 Jan 2026
    4.3
    Medium

    CVE-2026-20936

    Last Modified: 16 Apr 2026

    Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.

    Published: 13 Jan 2026
    6.2
    Medium

    CVE-2026-20935

    Last Modified: 16 Apr 2026

    Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally.

    Published: 13 Jan 2026
    8
    High

    CVE-2026-20931

    Last Modified: 26 May 2026

    External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.

    Published: 13 Jan 2026
    7.5
    High

    CVE-2026-20929

    Last Modified: 16 Apr 2026

    Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20874

    Last Modified: 16 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20873

    Last Modified: 16 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    6.5
    Medium

    CVE-2026-20872

    Last Modified: 16 Apr 2026

    External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

    Published: 13 Jan 2026