Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.7 MEDIUM
CVE-2026-21529 — Azure HDInsight Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network.

azure_hdinsights azure_hdinsight | Remote | Cross-Site Scripting
Feb 10, 2026 Feb 11, 2026
Feb 10, 2026
Feb 11, 2026
6.5 MEDIUM
CVE-2026-21528 — Azure IoT Explorer Information Disclosure Vulnerability

Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

azure_iot_explorer | Remote | Information Disclosure
Feb 10, 2026 Feb 19, 2026
Feb 10, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2026-21527 — Microsoft Exchange Server Spoofing Vulnerability

User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Feb 10, 2026 Feb 11, 2026
Feb 10, 2026
Feb 11, 2026
6.2 MEDIUM
CVE-2026-21525 — Microsoft Windows NULL Pointer Dereference Vulnerability - [Actively Exploited]

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

Feb 10, 2026 Feb 11, 2026
Feb 10, 2026
Feb 11, 2026
8.0 HIGH
CVE-2026-21523 — GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability

Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.

Feb 10, 2026 Feb 11, 2026
Feb 10, 2026
Feb 11, 2026
6.7 MEDIUM
CVE-2026-21522 — Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

Feb 10, 2026 Feb 11, 2026
Feb 10, 2026
Feb 11, 2026
7.8 HIGH
CVE-2026-21519 — Microsoft Windows Type Confusion Vulnerability - [Actively Exploited]

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

Feb 10, 2026 Feb 11, 2026
Feb 10, 2026
Feb 11, 2026
8.8 HIGH
CVE-2026-21518 — GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a networ…

Feb 10, 2026 Feb 23, 2026
Feb 10, 2026
Feb 23, 2026
7.0 HIGH
CVE-2026-21517 — Windows App for Mac Installer Elevation of Privilege Vulnerability

Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally.

windows_app windows_app_for_mac | Path Traversal
Feb 10, 2026 Feb 25, 2026
Feb 10, 2026
Feb 25, 2026
8.8 HIGH
CVE-2026-21516 — GitHub Copilot for Jetbrains Remote Code Execution Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network.

Feb 10, 2026 Feb 11, 2026
Feb 10, 2026
Feb 11, 2026
7.8 HIGH
CVE-2026-21514 — Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability -…

Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

Feb 10, 2026 Feb 11, 2026
Feb 10, 2026
Feb 11, 2026
8.8 HIGH
CVE-2026-21513 — Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability - [Actively Exploit…

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

Feb 10, 2026 Feb 11, 2026
Feb 10, 2026
Feb 11, 2026
6.5 MEDIUM
CVE-2026-21512 — Azure DevOps Server Cross-Site Scripting Vulnerability

Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network.

azure_devops_server azure_devops_server_2022 | Remote | Server-Side Request Forgery
Feb 10, 2026 Feb 11, 2026
Feb 10, 2026
Feb 11, 2026
7.5 HIGH
CVE-2026-21511 — Microsoft Outlook Spoofing Vulnerability

Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

Feb 10, 2026 Feb 11, 2026
Feb 10, 2026
Feb 11, 2026
8.8 HIGH
CVE-2026-21510 — Microsoft Windows Shell Protection Mechanism Failure Vulnerability - [Actively Exploited]

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

Feb 10, 2026 Feb 11, 2026
Feb 10, 2026
Feb 11, 2026
7.0 HIGH
CVE-2026-21508 — Windows Storage Elevation of Privilege Vulnerability

Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.

Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
5.5 MEDIUM
CVE-2026-21358 — InDesign Desktop | Heap-based Buffer Overflow (CWE-122)

InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in application denial-of-service. An attacker could exploit this vulner…

macos windows indesign | Memory Corruption
Feb 10, 2026 Feb 11, 2026
Feb 10, 2026
Feb 11, 2026
7.8 HIGH
CVE-2026-21357 — InDesign Desktop | Heap-based Buffer Overflow (CWE-122)

InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploit…

macos windows indesign | Memory Corruption
Feb 10, 2026 Feb 11, 2026
Feb 10, 2026
Feb 11, 2026
7.8 HIGH
CVE-2026-21351 — After Effects | Use After Free (CWE-416)

After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue req…

macos windows after_effects | Memory Corruption
Feb 10, 2026 Feb 11, 2026
Feb 10, 2026
Feb 11, 2026
5.5 MEDIUM
CVE-2026-21350 — After Effects | NULL Pointer Dereference (CWE-476)

After Effects versions 25.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to cras…

macos windows after_effects | Denial of Service
Feb 10, 2026 Feb 11, 2026
Feb 10, 2026
Feb 11, 2026
Showing 20 of 5092 Results