2026 CVE Vulnerabilities

64,952 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-76959MEDIUM4.6SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on c...
CVE-2026-44766MEDIUM6.5SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious in...
CVE-2026-82758MEDIUM6.3Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker...
CVE-2026-82757MEDIUM6.3Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who ...
CVE-2026-82756MEDIUM6.3Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthen...
CVE-2026-82755MEDIUM6.3Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a sha...
CVE-2026-82754MEDIUM6.3Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-ch...
CVE-2026-86436MEDIUM5.4Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing aut...
CVE-2026-86506MEDIUM5.9In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed prof...
CVE-2026-86500MEDIUM5.5In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant th...
CVE-2026-86499MEDIUM4.3In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of vis...
CVE-2026-86497MEDIUM6.8In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administra...
CVE-2026-86496MEDIUM4.3In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email...
CVE-2026-86495MEDIUM6.5In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccess...
CVE-2026-86493MEDIUM6.5In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteb...
CVE-2026-86490MEDIUM6.5In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app imp...
CVE-2026-86489MEDIUM6.5In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders a...
CVE-2026-86488MEDIUM6.5In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved se...
CVE-2026-86484MEDIUM4.6In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS
CVE-2026-86483MEDIUM5.4In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible
CVE-2026-86481MEDIUM4.3In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons
CVE-2026-80176MEDIUM4.7Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-80167MEDIUM5.5Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-80126MEDIUM6.5Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-80125MEDIUM5.9Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now