2026 CVE Vulnerabilities

64,751 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8813HIGH7.7This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an att...
CVE-2026-47311CRITICAL9.8Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Es...
CVE-2026-47310CRITICAL9.8Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issue affects Escargot: ...
CVE-2026-47309HIGH7.5Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Oversized Serialized Data Payloads. This is...
CVE-2026-47308HIGH7.5NULL pointer dereference vulnerability in Samsung Open Source Walrus allows Pointer Manipulation. This issue affects Wa...
CVE-2026-32994MEDIUM5.3The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8,...
CVE-2026-47307HIGH7.5NULL pointer dereference vulnerability in Samsung Open Source Walrus allows an attacker to cause a denial of service via...
CVE-2026-33565LOW3.3in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
CVE-2026-28751LOW3.3in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
CVE-2026-28733MEDIUM6.5in OpenHarmony v6.0 and prior versions allow a local attacker arbitrary code execution.
CVE-2026-27781LOW3.3in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
CVE-2026-27766MEDIUM5.5in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak.
CVE-2026-27648HIGH8.8in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.
CVE-2026-25850MEDIUM5.5in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak
CVE-2026-25781HIGH8.4in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.
CVE-2026-25110LOW3.3in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
CVE-2026-24792HIGH8.1in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.
CVE-2026-22069——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-33514MEDIUM4.3Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1...
CVE-2026-33234MEDIUM5AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-33233HIGH7.6AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-33232HIGH7.5AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-33052MEDIUM5.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.0 and 2.28.1 allow a low-privileged authent...
CVE-2026-32323HIGH7.8Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may...
CVE-2026-32312MEDIUM4.3GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with f...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now