2026 CVE Vulnerabilities
68,833 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2326 | — | — | — | Mar 16, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-2233 | MEDIUM | 5.3 | 0.2% | Mar 16, 2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP... |
| CVE-2026-28522 | HIGH | 7.1 | 0.3% | Mar 16, 2026 | arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An att... |
| CVE-2026-28521 | HIGH | 7.7 | 0.2% | Mar 16, 2026 | arduino-TuyaOpen before version 1.2.1 contains an out-of-bounds memory read vulnerability in the TuyaIoT component. An a... |
| CVE-2026-28520 | HIGH | 8.6 | 0.2% | Mar 16, 2026 | arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. W... |
| CVE-2026-28519 | HIGH | 8.8 | 0.4% | Mar 16, 2026 | arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An... |
| CVE-2026-26246 | MEDIUM | 4.3 | 0.2% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when process... |
| CVE-2026-26133 | HIGH | 7.1 | 0.4% | Mar 16, 2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-25783 | MEDIUM | 4.3 | 0.3% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header ... |
| CVE-2026-25780 | MEDIUM | 4.3 | 0.3% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when process... |
| CVE-2026-25083 | HIGH | 8.7 | 0.3% | Mar 16, 2026 | GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logg... |
| CVE-2026-24458 | HIGH | 7.5 | 0.3% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords,... |
| CVE-2026-21005 | MEDIUM | 6.5 | 0.2% | Mar 16, 2026 | Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Sm... |
| CVE-2026-21004 | MEDIUM | 6.5 | 0.2% | Mar 16, 2026 | Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of serv... |
| CVE-2026-21002 | MEDIUM | 5.5 | 0.1% | Mar 16, 2026 | Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to inst... |
| CVE-2026-21001 | MEDIUM | 5.5 | 0.1% | Mar 16, 2026 | Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privileg... |
| CVE-2026-21000 | MEDIUM | 5.5 | 0.1% | Mar 16, 2026 | Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store... |
| CVE-2026-20999 | HIGH | 7.5 | 0.3% | Mar 16, 2026 | Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged... |
| CVE-2026-20998 | CRITICAL | 9.8 | 0.5% | Mar 16, 2026 | Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication. |
| CVE-2026-20997 | CRITICAL | 9.8 | 0.3% | Mar 16, 2026 | Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to p... |
| CVE-2026-20996 | MEDIUM | 5.3 | 0.2% | Mar 16, 2026 | Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to c... |
| CVE-2026-20995 | MEDIUM | 5.3 | 0.3% | Mar 16, 2026 | Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote at... |
| CVE-2026-20994 | MEDIUM | 6.1 | 0.1% | Mar 16, 2026 | URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token. |
| CVE-2026-20993 | MEDIUM | 5.5 | 0.1% | Mar 16, 2026 | Improper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local attacker t... |
| CVE-2026-20992 | LOW | 3.3 | 0.1% | Mar 16, 2026 | Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the back... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now