2026 CVE Vulnerabilities

51,444 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-25783MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header ...
CVE-2026-25780MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when process...
CVE-2026-21005MEDIUM6.5Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Sm...
CVE-2026-21004MEDIUM6.5Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of serv...
CVE-2026-21002MEDIUM5.5Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to inst...
CVE-2026-21001MEDIUM5.5Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privileg...
CVE-2026-21000MEDIUM5.5Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store...
CVE-2026-20996MEDIUM5.3Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to c...
CVE-2026-20995MEDIUM5.3Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote at...
CVE-2026-20994MEDIUM6.1URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.
CVE-2026-20993MEDIUM5.5Improper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local attacker t...
CVE-2026-20991MEDIUM4.4Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse...
CVE-2026-20988MEDIUM5Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker ...
CVE-2026-1948MEDIUM4.3The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of d...
CVE-2026-1883MEDIUM4.3The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Inse...
CVE-2026-1870MEDIUM5.3The Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor plugin for WordPress is vulnerable to unauthori...
CVE-2026-0849MEDIUM6.8Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver...
CVE-2026-0639MEDIUM5.5in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory.
CVE-2026-0385MEDIUM5Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2026-4105MEDIUM6.7A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insuf...
CVE-2026-4063MEDIUM4.3The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a ...
CVE-2026-3986MEDIUM6.4The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form settings in al...
CVE-2026-32745MEDIUM5.7In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings
CVE-2026-32612MEDIUM5.4Statamic is a Laravel and Git powered content management system (CMS). Prior to 6.6.2, stored XSS in the control panel c...
CVE-2026-32598MEDIUM6.5OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now