2026 CVE Vulnerabilities
61,653 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11603 | MEDIUM | 6.1 | 0.2% | Jun 9, 2026 | The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'args[f... |
| CVE-2026-10738 | MEDIUM | 6.4 | 0.3% | Jun 9, 2026 | The jQuery Hover Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Footnote Qualifier ('{{... |
| CVE-2026-10553 | MEDIUM | 4.3 | 0.1% | Jun 9, 2026 | The jQuery Hover Footnotes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2026-10024 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The TinyMCE shortcode Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'btnrel' Shortcode Att... |
| CVE-2026-7556 | HIGH | 7.2 | 0.2% | Jun 9, 2026 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in... |
| CVE-2026-5714 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘location_dir’ parame... |
| CVE-2026-11621 | MEDIUM | 4.7 | 0.2% | Jun 9, 2026 | A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /adm... |
| CVE-2026-11620 | MEDIUM | 5.5 | 0.3% | Jun 9, 2026 | A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsf... |
| CVE-2026-11619 | MEDIUM | 6.3 | 0.2% | Jun 9, 2026 | A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file... |
| CVE-2026-11618 | HIGH | 7.3 | 0.4% | Jun 9, 2026 | A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function preHandle of the file ... |
| CVE-2026-10862 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all ver... |
| CVE-2026-8795 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version... |
| CVE-2026-44757 | MEDIUM | 4.7 | 0.2% | Jun 9, 2026 | SAP Wily Introscope Enterprise Manager allows an unauthenticated attacker to craft a specially crafted URL. Under certai... |
| CVE-2026-44755 | MEDIUM | 4.3 | 0.1% | Jun 9, 2026 | SAP Business Objects Business Intelligence Platform does not sufficiently validate email sending parameters supplied by ... |
| CVE-2026-44754 | MEDIUM | 6.6 | 0.2% | Jun 9, 2026 | The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (ODP-RFC) are missing c... |
| CVE-2026-44751 | HIGH | 7.1 | 0.2% | Jun 9, 2026 | Application server ABAP does not perform necessary authorization checks for an authenticated user allowing an attacker t... |
| CVE-2026-44750 | MEDIUM | 4.3 | 0.2% | Jun 9, 2026 | SAP MDG (Review Match Groups Application) does not perform the necessary authorization checks for authenticated users. T... |
| CVE-2026-44748 | CRITICAL | 9.9 | 0.2% | Jun 9, 2026 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtai... |
| CVE-2026-44746 | MEDIUM | 6.1 | 0.2% | Jun 9, 2026 | Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticate... |
| CVE-2026-44744 | MEDIUM | 6.5 | 0.2% | Jun 9, 2026 | SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module component that could be... |
| CVE-2026-44743 | LOW | 3.7 | 0.2% | Jun 9, 2026 | Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application l... |
| CVE-2026-40128 | CRITICAL | 9 | 0.5% | Jun 9, 2026 | SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon... |
| CVE-2026-27671 | CRITICAL | 9.8 | 0.4% | Jun 9, 2026 | Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP ... |
| CVE-2026-24315 | MEDIUM | 4.2 | 0.2% | Jun 9, 2026 | SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, ... |
| CVE-2026-11701 | MEDIUM | 5.4 | 0.2% | Jun 9, 2026 | Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now