2026 CVE Vulnerabilities

68,833 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-2326——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-2233MEDIUM5.3The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-28522HIGH7.1arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An att...
CVE-2026-28521HIGH7.7arduino-TuyaOpen before version 1.2.1 contains an out-of-bounds memory read vulnerability in the TuyaIoT component. An a...
CVE-2026-28520HIGH8.6arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. W...
CVE-2026-28519HIGH8.8arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An...
CVE-2026-26246MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when process...
CVE-2026-26133HIGH7.1AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-25783MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header ...
CVE-2026-25780MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when process...
CVE-2026-25083HIGH8.7GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logg...
CVE-2026-24458HIGH7.5Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords,...
CVE-2026-21005MEDIUM6.5Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Sm...
CVE-2026-21004MEDIUM6.5Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of serv...
CVE-2026-21002MEDIUM5.5Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to inst...
CVE-2026-21001MEDIUM5.5Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privileg...
CVE-2026-21000MEDIUM5.5Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store...
CVE-2026-20999HIGH7.5Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged...
CVE-2026-20998CRITICAL9.8Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.
CVE-2026-20997CRITICAL9.8Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to p...
CVE-2026-20996MEDIUM5.3Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to c...
CVE-2026-20995MEDIUM5.3Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote at...
CVE-2026-20994MEDIUM6.1URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.
CVE-2026-20993MEDIUM5.5Improper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local attacker t...
CVE-2026-20992LOW3.3Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the back...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now