2026 CVE Vulnerabilities

61,772 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28578MEDIUM5.5In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper in...
CVE-2026-28577HIGH7.8In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This...
CVE-2026-10294MEDIUM4.3A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transa...
CVE-2026-10293HIGH8.8A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/formF...
CVE-2026-10292HIGH8.8A vulnerability was detected in UTT HiPER 1200GW up to 2.5.3-170306. This affects the function strcpy of the file /gofor...
CVE-2026-10291MEDIUM5.3A security vulnerability has been detected in Enderfga claw-orchestrator up to 3.7.0. The impacted element is the functi...
CVE-2026-10290HIGH7.3A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unk...
CVE-2026-0100HIGH7.8In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to loc...
CVE-2026-0099HIGH7.8In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to ...
CVE-2026-0098HIGH7.8In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused...
CVE-2026-0097HIGH8In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error...
CVE-2026-0096HIGH7.8In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to mi...
CVE-2026-0095HIGH8In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged ...
CVE-2026-0094HIGH7.8In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to cert...
CVE-2026-0093HIGH7.8In multiple locations, there is a possible misleading UI due to obfuscation. This could lead to local escalation of priv...
CVE-2026-0091HIGH7.8In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell u...
CVE-2026-0089HIGH7.8In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missi...
CVE-2026-0088HIGH7.8In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to mislea...
CVE-2026-0087HIGH7.8In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app ...
CVE-2026-0086MEDIUM6.8In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null c...
CVE-2026-0085MEDIUM5.5In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to imprope...
CVE-2026-0080MEDIUM6.5In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow...
CVE-2026-0079MEDIUM5.5In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer ...
CVE-2026-0078HIGH7.8In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input va...
CVE-2026-0077HIGH7.8In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now