2026 CVE Vulnerabilities

48,877 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-50260HIGH7.8A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple Sync...
CVE-2026-50259HIGH7.8A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-siz...
CVE-2026-50258HIGH7.8A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers...
CVE-2026-50257HIGH7.8A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multip...
CVE-2026-50256HIGH7.8A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the...
CVE-2026-8914HIGH8.4In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 throug...
CVE-2026-21037HIGH7.1Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL an...
CVE-2026-21035HIGH7.5Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive infor...
CVE-2026-21033HIGH7.1Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3...
CVE-2026-21032HIGH7.1Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.1...
CVE-2026-21031HIGH7.8Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. U...
CVE-2026-21030HIGH7.8Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileg...
CVE-2026-21029HIGH7.8Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local...
CVE-2026-11347HIGH8.5The linqi application contains hardcoded cryptographic keys. Additionally, the application uses a weak algorithm with a ...
CVE-2026-11332HIGH7.8A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a rol...
CVE-2026-21837HIGH8.8HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An att...
CVE-2026-50593HIGH7.3Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat d...
CVE-2026-41567HIGH7.2Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, whe...
CVE-2026-50589HIGH7.5In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpo...
CVE-2026-11307HIGH8.8Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-11306HIGH8.8Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-11305HIGH8.8Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-11304HIGH8.8Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap c...
CVE-2026-11303HIGH8.8Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-11301HIGH8.8Inappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potenti...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now