2026 CVE Vulnerabilities
64,889 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21112 | MEDIUM | 5.5 | 0.1% | Sep 9, 2026 | Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with S... |
| CVE-2026-21111 | MEDIUM | 6.9 | 0.1% | Sep 9, 2026 | Out-of-bounds write in libsthmbc.so prior to One UI 8.5 allows local attackers to write out-of-bounds memory. |
| CVE-2026-21110 | MEDIUM | 6.9 | 0.1% | Sep 9, 2026 | Out-of-bounds write in libsavscmn.so prior to One UI 8.5 allows local attackers to execute arbitrary code. |
| CVE-2026-21108 | MEDIUM | 5.5 | 0.1% | Sep 9, 2026 | Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to ac... |
| CVE-2026-21107 | MEDIUM | 5.5 | 0.1% | Sep 9, 2026 | Out-of-bounds write in Samsung Notes prior to version 4.4.45.5 allows local attackers to write out-of-bounds memory. |
| CVE-2026-21106 | MEDIUM | 5.1 | 0.1% | Sep 9, 2026 | Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local att... |
| CVE-2026-21105 | MEDIUM | 5.5 | 0.1% | Sep 9, 2026 | Improper access control in Collection prior to version 1.0.1.14 in Android 15 and 2.0.02.7 in Android 16 allows local at... |
| CVE-2026-21104 | MEDIUM | 6.7 | 0.1% | Sep 9, 2026 | Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to ex... |
| CVE-2026-21103 | MEDIUM | 6.1 | 0.2% | Sep 9, 2026 | Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with syste... |
| CVE-2026-21102 | MEDIUM | 6.7 | 0.1% | Sep 9, 2026 | Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code wi... |
| CVE-2026-21101 | MEDIUM | 6.7 | 0.1% | Sep 9, 2026 | Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potenti... |
| CVE-2026-21099 | MEDIUM | 5.5 | 0.1% | Sep 9, 2026 | Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive i... |
| CVE-2026-21098 | MEDIUM | 6.9 | 0.1% | Sep 9, 2026 | Improper access control in Link to Windows prior to SMR Sep-2026 Release 1 allows local attackers to establish a connect... |
| CVE-2026-21097 | MEDIUM | 6.7 | 0.1% | Sep 9, 2026 | Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers ... |
| CVE-2026-21093 | MEDIUM | 6.7 | 0.1% | Sep 9, 2026 | Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write... |
| CVE-2026-21092 | MEDIUM | 5.3 | 0.4% | Sep 9, 2026 | Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system s... |
| CVE-2026-21086 | MEDIUM | 4.8 | 0.1% | Sep 9, 2026 | Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configurat... |
| CVE-2026-21085 | MEDIUM | 6.7 | 0.1% | Sep 9, 2026 | Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out... |
| CVE-2026-19945 | MEDIUM | 6.4 | 0.2% | Sep 9, 2026 | The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in ... |
| CVE-2026-11821 | MEDIUM | 5.4 | 0.2% | Sep 9, 2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to a... |
| CVE-2026-81647 | MEDIUM | 5.3 | 0.2% | Sep 9, 2026 | Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affec... |
| CVE-2026-81646 | MEDIUM | 5.9 | 0.1% | Sep 9, 2026 | Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affec... |
| CVE-2026-81644 | MEDIUM | 4.3 | 0.1% | Sep 9, 2026 | DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availa... |
| CVE-2026-7804 | MEDIUM | 6.1 | 0.3% | Sep 9, 2026 | The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '... |
| CVE-2026-77187 | MEDIUM | 6.4 | 0.2% | Sep 9, 2026 | The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'before... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now