2026 CVE Vulnerabilities

70,367 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-0017HIGH7.7In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the c...
CVE-2026-0015MEDIUM6.2In multiple locations of AppOpsService.java, there is a possible persistent denial of service due to improper input vali...
CVE-2026-0014MEDIUM6.2In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input v...
CVE-2026-0013HIGH8.4In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confuse...
CVE-2026-0012MEDIUM6.2In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in...
CVE-2026-0011HIGH8.4In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a log...
CVE-2026-0010HIGH8.4In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This cou...
CVE-2026-0008HIGH8.4In multiple functions of FaceEnroll.kt, there is a possible privilege escalation due to a confused deputy. This could le...
CVE-2026-0007HIGH8.6In writeToParcel of WindowInfo.cpp, there is a possible way to trick a user into accepting a permission due to a tapjack...
CVE-2026-0006CRITICAL9.8In multiple locations, there is a possible out of bounds read and write due to a heap buffer overflow. This could lead t...
CVE-2026-0005MEDIUM6.2In onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing lim...
CVE-2026-3180HIGH7.5The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind...
CVE-2026-3132HIGH8.8The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up t...
CVE-2026-26707CRITICAL9.8sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php.
CVE-2026-26706CRITICAL9.8sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_receipt.php.
CVE-2026-26705CRITICAL9.8sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_product.php.
CVE-2026-26704CRITICAL9.8sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_category.php.
CVE-2026-0655HIGH8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TP-Link Deco BE25 v1.0 (...
CVE-2026-0654HIGH8Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be execute...
CVE-2026-28401MEDIUM5.4NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, rich text cell content rendered via...
CVE-2026-28399HIGH8.8NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, an authenticated user with Creator ...
CVE-2026-28398MEDIUM5.4NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, user-controlled content in comments...
CVE-2026-28397MEDIUM5.4NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, comments rendered via v-html withou...
CVE-2026-28396MEDIUM6.5NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password reset flow did not rev...
CVE-2026-28361MEDIUM6.3NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the MCP token service did not valid...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now