Skip to main content

Year archive

CVEs published in 2026

Archive summary

42,966 CVEs published in 2026 — 4,543 Critical, 17,071 High, 17,284 Medium, 3,586 Low, 482 Unrated.

CVE-2025-68701

Published Jan 13, 2026

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses deterministic AES IV derivation from a passphrase. This vulnerabili…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-68698

Published Jan 13, 2026

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses PKCS1Encoding which is vulnerable to Bleichenbacher padding oracle…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-37179

Published Jan 13, 2026

Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer s…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-37178

Published Jan 13, 2026

Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer s…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-37177

Published Jan 13, 2026

An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful expl…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-37176

Published Jan 13, 2026

A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject shell commands, potentially affecting the execution of inter…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-37175

Published Jan 13, 2026

Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation c…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-37174

Published Jan 13, 2026

Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful e…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-37173

Published Jan 13, 2026

An improper input handling vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitat…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-37172

Published Jan 13, 2026

Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could al…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-37171

Published Jan 13, 2026

Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could al…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-37170

Published Jan 13, 2026

Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could al…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-37169

Published Jan 13, 2026

A stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway. Successful exploitation could allow an authenticated malicious actor to e…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-37168

Published Jan 13, 2026

Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 operating system. Successful exploitation of this vulnerabilit…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2026-22791

Published Jan 13, 2026

openCryptoki is a PKCS#11 library and tools for Linux and AIX. In 3.25.0 and 3.26.0, there is a heap buffer overflow vulnerability in the CKM_ECDH_AES_KEY_WRAP implementation allo…

CVSS 6.6 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-21288

Published Jan 13, 2026

Illustrator versions 29.8.3, 30.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21280

Published Jan 13, 2026

Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current us…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21278

Published Jan 13, 2026

InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerab…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21276

Published Jan 13, 2026

InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21275

Published Jan 13, 2026

InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21274

Published Jan 13, 2026

Dreamweaver Desktop versions 21.6 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 41,426-41,450 of 42,966 CVEsPage 1658 of 1719