2026 CVE Vulnerabilities

57,035 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40007HIGH7.5Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enab...
CVE-2026-40006HIGH7.5Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authenticatio...
CVE-2026-40005CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. An attacke...
CVE-2026-28564CRITICAL9.8Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authe...
CVE-2026-13347HIGH7.5The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 1.3 via th...
CVE-2026-12685HIGH7.5The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that let...
CVE-2026-12276MEDIUM5.3The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user registration is enable...
CVE-2026-12123MEDIUM6.4The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an...
CVE-2026-21057MEDIUM6.8Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bo...
CVE-2026-21056MEDIUM4.8Improper authorization in Samsung Health prior to version 7.00.0.107 allows local attackers to access connected device i...
CVE-2026-21055HIGH8.5Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute a...
CVE-2026-21054MEDIUM6.9Improper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to ac...
CVE-2026-21053MEDIUM5.1Improper input validation in Samsung Email prior to version 6.2.13.1 allows local attackers to create arbitrary files wi...
CVE-2026-21052MEDIUM6.8Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files ...
CVE-2026-21051MEDIUM5.1Incorrect default permissions in WLAN security prior to SMR Jul-2026 Release 1 allows local attackers to configure Tence...
CVE-2026-21050MEDIUM5.1Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive inf...
CVE-2026-21049HIGH8.4Out-of-bounds write in libpadm.so library prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary co...
CVE-2026-21048HIGH8.3Out-of-bounds write in parsing DNG format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote ...
CVE-2026-21046HIGH8.4Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privil...
CVE-2026-21045HIGH8.3Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote...
CVE-2026-21044MEDIUM5.8Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persiste...
CVE-2026-21043MEDIUM6.7Path traversal in Wallpaper service prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files wi...
CVE-2026-21042HIGH8.7Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows remote attackers to execute arbitrary code.
CVE-2026-21041MEDIUM6.9Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensit...
CVE-2026-21040MEDIUM6.9Improper access control in IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attackers to use the priv...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now