2026 CVE Vulnerabilities

61,684 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-21037HIGH7.1Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL an...
CVE-2026-21036MEDIUM5.5Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive informa...
CVE-2026-21035HIGH7.5Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive infor...
CVE-2026-21034LOW3.3Improper export of android application components in Samsung Auto prior to version 3.1.2.61 in Android 15 and 3.2.0.38 i...
CVE-2026-21033HIGH7.1Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3...
CVE-2026-21032HIGH7.1Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.1...
CVE-2026-21031HIGH7.8Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. U...
CVE-2026-21030HIGH7.8Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileg...
CVE-2026-21029HIGH7.8Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local...
CVE-2026-21028MEDIUM5.5Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive in...
CVE-2026-21027LOW3.3Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers ...
CVE-2026-21026MEDIUM5.5Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attack...
CVE-2026-21025MEDIUM5.5Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive i...
CVE-2026-21017MEDIUM5.5Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attack...
CVE-2026-11347HIGH8.5The linqi application contains hardcoded cryptographic keys. Additionally, the application uses a weak algorithm with a ...
CVE-2026-6274CRITICAL9.8Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electron...
CVE-2026-49777CRITICAL10Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce...
CVE-2026-11332HIGH7.8A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a rol...
CVE-2026-9088LOW2.7A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users ca...
CVE-2026-48907CRITICAL9.8A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated us...
CVE-2026-21837HIGH8.8HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An att...
CVE-2026-21826MEDIUM6.1HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker ca...
CVE-2026-21825MEDIUM6.1HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center....
CVE-2026-10732MEDIUM6.4All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when ext...
CVE-2026-50593HIGH7.3Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat d...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now