2026 CVE Vulnerabilities
51,444 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25783 | MEDIUM | 4.3 | 0.3% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header ... |
| CVE-2026-25780 | MEDIUM | 4.3 | 0.3% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when process... |
| CVE-2026-21005 | MEDIUM | 6.5 | 0.2% | Mar 16, 2026 | Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Sm... |
| CVE-2026-21004 | MEDIUM | 6.5 | 0.2% | Mar 16, 2026 | Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of serv... |
| CVE-2026-21002 | MEDIUM | 5.5 | 0.1% | Mar 16, 2026 | Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to inst... |
| CVE-2026-21001 | MEDIUM | 5.5 | 0.1% | Mar 16, 2026 | Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privileg... |
| CVE-2026-21000 | MEDIUM | 5.5 | 0.1% | Mar 16, 2026 | Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store... |
| CVE-2026-20996 | MEDIUM | 5.3 | 0.2% | Mar 16, 2026 | Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to c... |
| CVE-2026-20995 | MEDIUM | 5.3 | 0.3% | Mar 16, 2026 | Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote at... |
| CVE-2026-20994 | MEDIUM | 6.1 | 0.1% | Mar 16, 2026 | URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token. |
| CVE-2026-20993 | MEDIUM | 5.5 | 0.1% | Mar 16, 2026 | Improper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local attacker t... |
| CVE-2026-20991 | MEDIUM | 4.4 | 0.1% | Mar 16, 2026 | Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse... |
| CVE-2026-20988 | MEDIUM | 5 | 0.1% | Mar 16, 2026 | Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker ... |
| CVE-2026-1948 | MEDIUM | 4.3 | 0.2% | Mar 16, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of d... |
| CVE-2026-1883 | MEDIUM | 4.3 | 0.2% | Mar 16, 2026 | The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Inse... |
| CVE-2026-1870 | MEDIUM | 5.3 | 0.3% | Mar 16, 2026 | The Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor plugin for WordPress is vulnerable to unauthori... |
| CVE-2026-0849 | MEDIUM | 6.8 | 0.2% | Mar 16, 2026 | Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver... |
| CVE-2026-0639 | MEDIUM | 5.5 | 0.2% | Mar 16, 2026 | in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory. |
| CVE-2026-0385 | MEDIUM | 5 | 0.2% | Mar 16, 2026 | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability |
| CVE-2026-4105 | MEDIUM | 6.7 | 0.1% | Mar 13, 2026 | A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insuf... |
| CVE-2026-4063 | MEDIUM | 4.3 | 0.2% | Mar 13, 2026 | The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a ... |
| CVE-2026-3986 | MEDIUM | 6.4 | 0.2% | Mar 13, 2026 | The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form settings in al... |
| CVE-2026-32745 | MEDIUM | 5.7 | 0.1% | Mar 13, 2026 | In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings |
| CVE-2026-32612 | MEDIUM | 5.4 | 0.2% | Mar 13, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 6.6.2, stored XSS in the control panel c... |
| CVE-2026-32598 | MEDIUM | 6.5 | 0.2% | Mar 13, 2026 | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now