2026 CVE Vulnerabilities
70,367 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0017 | HIGH | 7.7 | 0.1% | Mar 2, 2026 | In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the c... |
| CVE-2026-0015 | MEDIUM | 6.2 | 0.1% | Mar 2, 2026 | In multiple locations of AppOpsService.java, there is a possible persistent denial of service due to improper input vali... |
| CVE-2026-0014 | MEDIUM | 6.2 | 0.1% | Mar 2, 2026 | In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input v... |
| CVE-2026-0013 | HIGH | 8.4 | 0.1% | Mar 2, 2026 | In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confuse... |
| CVE-2026-0012 | MEDIUM | 6.2 | 0.1% | Mar 2, 2026 | In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in... |
| CVE-2026-0011 | HIGH | 8.4 | 0.1% | Mar 2, 2026 | In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a log... |
| CVE-2026-0010 | HIGH | 8.4 | 0.1% | Mar 2, 2026 | In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This cou... |
| CVE-2026-0008 | HIGH | 8.4 | 0.1% | Mar 2, 2026 | In multiple functions of FaceEnroll.kt, there is a possible privilege escalation due to a confused deputy. This could le... |
| CVE-2026-0007 | HIGH | 8.6 | 0.1% | Mar 2, 2026 | In writeToParcel of WindowInfo.cpp, there is a possible way to trick a user into accepting a permission due to a tapjack... |
| CVE-2026-0006 | CRITICAL | 9.8 | 0.6% | Mar 2, 2026 | In multiple locations, there is a possible out of bounds read and write due to a heap buffer overflow. This could lead t... |
| CVE-2026-0005 | MEDIUM | 6.2 | 0.1% | Mar 2, 2026 | In onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing lim... |
| CVE-2026-3180 | HIGH | 7.5 | 0.7% | Mar 2, 2026 | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind... |
| CVE-2026-3132 | HIGH | 8.8 | 0.6% | Mar 2, 2026 | The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up t... |
| CVE-2026-26707 | CRITICAL | 9.8 | 0.5% | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php. |
| CVE-2026-26706 | CRITICAL | 9.8 | 0.5% | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_receipt.php. |
| CVE-2026-26705 | CRITICAL | 9.8 | 0.4% | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_product.php. |
| CVE-2026-26704 | CRITICAL | 9.8 | 0.4% | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_category.php. |
| CVE-2026-0655 | HIGH | 8 | 0.3% | Mar 2, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TP-Link Deco BE25 v1.0 (... |
| CVE-2026-0654 | HIGH | 8 | 0.3% | Mar 2, 2026 | Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be execute... |
| CVE-2026-28401 | MEDIUM | 5.4 | 0.2% | Mar 2, 2026 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, rich text cell content rendered via... |
| CVE-2026-28399 | HIGH | 8.8 | 0.3% | Mar 2, 2026 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, an authenticated user with Creator ... |
| CVE-2026-28398 | MEDIUM | 5.4 | 0.1% | Mar 2, 2026 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, user-controlled content in comments... |
| CVE-2026-28397 | MEDIUM | 5.4 | 0.2% | Mar 2, 2026 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, comments rendered via v-html withou... |
| CVE-2026-28396 | MEDIUM | 6.5 | 0.2% | Mar 2, 2026 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password reset flow did not rev... |
| CVE-2026-28361 | MEDIUM | 6.3 | 0.2% | Mar 2, 2026 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the MCP token service did not valid... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now