2026 CVE Vulnerabilities

61,653 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-11603MEDIUM6.1The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'args[f...
CVE-2026-10738MEDIUM6.4The jQuery Hover Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Footnote Qualifier ('{{...
CVE-2026-10553MEDIUM4.3The jQuery Hover Footnotes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2026-10024MEDIUM6.4The TinyMCE shortcode Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'btnrel' Shortcode Att...
CVE-2026-7556HIGH7.2The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in...
CVE-2026-5714MEDIUM6.4The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘location_dir’ parame...
CVE-2026-11621MEDIUM4.7A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /adm...
CVE-2026-11620MEDIUM5.5A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsf...
CVE-2026-11619MEDIUM6.3A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file...
CVE-2026-11618HIGH7.3A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function preHandle of the file ...
CVE-2026-10862MEDIUM6.4The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all ver...
CVE-2026-8795HIGH7.8A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version...
CVE-2026-44757MEDIUM4.7SAP Wily Introscope Enterprise Manager allows an unauthenticated attacker to craft a specially crafted URL. Under certai...
CVE-2026-44755MEDIUM4.3SAP Business Objects Business Intelligence Platform does not sufficiently validate email sending parameters supplied by ...
CVE-2026-44754MEDIUM6.6The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (ODP-RFC) are missing c...
CVE-2026-44751HIGH7.1Application server ABAP does not perform necessary authorization checks for an authenticated user allowing an attacker t...
CVE-2026-44750MEDIUM4.3SAP MDG (Review Match Groups Application) does not perform the necessary authorization checks for authenticated users. T...
CVE-2026-44748CRITICAL9.9SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtai...
CVE-2026-44746MEDIUM6.1Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticate...
CVE-2026-44744MEDIUM6.5SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module component that could be...
CVE-2026-44743LOW3.7Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application l...
CVE-2026-40128CRITICAL9SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon...
CVE-2026-27671CRITICAL9.8Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP ...
CVE-2026-24315MEDIUM4.2SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, ...
CVE-2026-11701MEDIUM5.4Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now