2026 CVE Vulnerabilities

61,555 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-26236HIGH7.5A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vul...
CVE-2026-11623MEDIUM4.5A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c. ...
CVE-2026-11603MEDIUM6.1The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'args[f...
CVE-2026-10738MEDIUM6.4The jQuery Hover Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Footnote Qualifier ('{{...
CVE-2026-10553MEDIUM4.3The jQuery Hover Footnotes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2026-10024MEDIUM6.4The TinyMCE shortcode Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'btnrel' Shortcode Att...
CVE-2026-7556HIGH7.2The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in...
CVE-2026-5714MEDIUM6.4The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘location_dir’ parame...
CVE-2026-11621MEDIUM4.7A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /adm...
CVE-2026-11620MEDIUM5.5A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsf...
CVE-2026-11619MEDIUM6.3A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file...
CVE-2026-11618HIGH7.3A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function preHandle of the file ...
CVE-2026-10862MEDIUM6.4The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all ver...
CVE-2026-8795HIGH7.8A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version...
CVE-2026-44757MEDIUM4.7SAP Wily Introscope Enterprise Manager allows an unauthenticated attacker to craft a specially crafted URL. Under certai...
CVE-2026-44755MEDIUM4.3SAP Business Objects Business Intelligence Platform does not sufficiently validate email sending parameters supplied by ...
CVE-2026-44754MEDIUM6.6The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (ODP-RFC) are missing c...
CVE-2026-44751HIGH7.1Application server ABAP does not perform necessary authorization checks for an authenticated user allowing an attacker t...
CVE-2026-44750MEDIUM4.3SAP MDG (Review Match Groups Application) does not perform the necessary authorization checks for authenticated users. T...
CVE-2026-44748CRITICAL9.9SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtai...
CVE-2026-44746MEDIUM6.1Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticate...
CVE-2026-44744MEDIUM6.5SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module component that could be...
CVE-2026-44743LOW3.7Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application l...
CVE-2026-40128CRITICAL9SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon...
CVE-2026-27671CRITICAL9.8Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now