2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-0091HIGH7.8In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell u...
CVE-2026-0089HIGH7.8In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missi...
CVE-2026-0088HIGH7.8In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to mislea...
CVE-2026-0087HIGH7.8In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app ...
CVE-2026-0078HIGH7.8In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input va...
CVE-2026-0077HIGH7.8In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a ...
CVE-2026-0076HIGH7.8In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bounds check. This coul...
CVE-2026-0059HIGH8In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overfl...
CVE-2026-0045HIGH7.8In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connection due to a logic ...
CVE-2026-0036HIGH7.8In startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. Thi...
CVE-2026-0009HIGH7.8In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalat...
CVE-2026-49139HIGH7Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handl...
CVE-2026-49136HIGH8.7Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() ...
CVE-2026-49135HIGH7.2CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to acces...
CVE-2026-49134HIGH7.5CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers ...
CVE-2026-37234HIGH8.2FlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by sending multiple E42_SETUP_REQUESTs. On disc...
CVE-2026-24751HIGH8.2Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Dat...
CVE-2026-10288HIGH7.3A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the functio...
CVE-2026-10287HIGH7.3A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get...
CVE-2026-9614HIGH8.8An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticate...
CVE-2026-9330HIGH8.5IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deseria...
CVE-2026-7770HIGH8.8IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution ...
CVE-2026-47294HIGH8Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoin...
CVE-2026-45727HIGH8.8CloakBrowser is a tool to bypass bot detection tests. Prior to version 0.3.28, the cloakserve CDP multiplexer uses the u...
CVE-2026-45722HIGH7.1Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now