2026 CVE Vulnerabilities
57,035 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40007 | HIGH | 7.5 | 0.1% | Jul 10, 2026 | Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enab... |
| CVE-2026-40006 | HIGH | 7.5 | 0.2% | Jul 10, 2026 | Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authenticatio... |
| CVE-2026-40005 | CRITICAL | 9.1 | 0.2% | Jul 10, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. An attacke... |
| CVE-2026-28564 | CRITICAL | 9.8 | 0.2% | Jul 10, 2026 | Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authe... |
| CVE-2026-13347 | HIGH | 7.5 | 0.5% | Jul 10, 2026 | The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 1.3 via th... |
| CVE-2026-12685 | HIGH | 7.5 | 0.1% | Jul 10, 2026 | The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that let... |
| CVE-2026-12276 | MEDIUM | 5.3 | 0.1% | Jul 10, 2026 | The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user registration is enable... |
| CVE-2026-12123 | MEDIUM | 6.4 | 0.2% | Jul 10, 2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an... |
| CVE-2026-21057 | MEDIUM | 6.8 | 0.1% | Jul 10, 2026 | Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bo... |
| CVE-2026-21056 | MEDIUM | 4.8 | 0.1% | Jul 10, 2026 | Improper authorization in Samsung Health prior to version 7.00.0.107 allows local attackers to access connected device i... |
| CVE-2026-21055 | HIGH | 8.5 | 0.1% | Jul 10, 2026 | Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute a... |
| CVE-2026-21054 | MEDIUM | 6.9 | 0.1% | Jul 10, 2026 | Improper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to ac... |
| CVE-2026-21053 | MEDIUM | 5.1 | 0.1% | Jul 10, 2026 | Improper input validation in Samsung Email prior to version 6.2.13.1 allows local attackers to create arbitrary files wi... |
| CVE-2026-21052 | MEDIUM | 6.8 | 0.1% | Jul 10, 2026 | Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files ... |
| CVE-2026-21051 | MEDIUM | 5.1 | 0.1% | Jul 10, 2026 | Incorrect default permissions in WLAN security prior to SMR Jul-2026 Release 1 allows local attackers to configure Tence... |
| CVE-2026-21050 | MEDIUM | 5.1 | 0.1% | Jul 10, 2026 | Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive inf... |
| CVE-2026-21049 | HIGH | 8.4 | 0.1% | Jul 10, 2026 | Out-of-bounds write in libpadm.so library prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary co... |
| CVE-2026-21048 | HIGH | 8.3 | 0.4% | Jul 10, 2026 | Out-of-bounds write in parsing DNG format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote ... |
| CVE-2026-21046 | HIGH | 8.4 | 0.1% | Jul 10, 2026 | Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privil... |
| CVE-2026-21045 | HIGH | 8.3 | 0.4% | Jul 10, 2026 | Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote... |
| CVE-2026-21044 | MEDIUM | 5.8 | 0.1% | Jul 10, 2026 | Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persiste... |
| CVE-2026-21043 | MEDIUM | 6.7 | 0.1% | Jul 10, 2026 | Path traversal in Wallpaper service prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files wi... |
| CVE-2026-21042 | HIGH | 8.7 | 0.2% | Jul 10, 2026 | Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows remote attackers to execute arbitrary code. |
| CVE-2026-21041 | MEDIUM | 6.9 | 0.1% | Jul 10, 2026 | Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensit... |
| CVE-2026-21040 | MEDIUM | 6.9 | 0.1% | Jul 10, 2026 | Improper access control in IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attackers to use the priv... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now