Substance 3d Stager
Vendor:
First CVE: Mar 27, 2023 · Active for 3 years
87
Total CVEs
More Total CVEs than 99% of tracked products
21.8
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Substance 3d Stager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 27, 2023
3 years ago
Most Recent CVE
Mar 27, 2026
123 days ago
CVE Severity & Scoring
Substance 3d Stager87 CVEs
24%
76%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local87 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low87 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required87 (100.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None87 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (87 CVEs).
87 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27309HIGH Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exp | Mar 27, 2026 | 7.8 | 27 | NO | NO |
CVE-2026-27274HIGH Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current use | Mar 10, 2026 | 7.8 | 27 | NO | NO |
CVE-2026-27277HIGH Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exp | Mar 10, 2026 | 7.8 | 26 | NO | NO |
CVE-2026-27276HIGH Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exp | Mar 10, 2026 | 7.8 | 26 | NO | NO |
CVE-2026-27275HIGH Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current use | Mar 10, 2026 | 7.8 | 26 | NO | NO |
CVE-2026-27273HIGH Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current use | Mar 10, 2026 | 7.8 | 26 | NO | NO |
CVE-2025-61805HIGH Substance3D - Stager versions 3.1.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an all | Oct 14, 2025 | 7.8 | 26 | NO | NO |
CVE-2025-54262HIGH Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an all | Sep 16, 2025 | 7.8 | 26 | NO | NO |
CVE-2026-21345HIGH Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an all | Feb 10, 2026 | 7.8 | 25 | NO | NO |
CVE-2026-21343HIGH Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an all | Feb 10, 2026 | 7.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (87 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (87 CVEs).
Media Mentions
Signals from CVEs in this product scope (87 CVEs).
Top CNAs Publishing CVEs For Substance 3d Stager
Top CWEs
Versions
No cataloged versions.