2026 CVE Vulnerabilities

43,891 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-44769MEDIUM5.5SAP S/4HANA application Project Management (PPM-PRO) allows an attacker with high privileges to execute crafted database...
CVE-2026-44768MEDIUM4.1SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to...
CVE-2026-44767MEDIUM6.1setThemeRoot() failed to enforce the sap-allowed-theme-origins allowlist. An attacker-controlled absolute cross-origin U...
CVE-2026-44760MEDIUM4.7Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SAP NetWeave...
CVE-2026-44759MEDIUM6.1SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The...
CVE-2026-15621MEDIUM5.3A vulnerability was detected in mosaxiv clawlet up to 0.2.10. This impacts the function read_file/write_file/edit_file o...
CVE-2026-15620MEDIUM6.3A security vulnerability has been detected in mosaxiv clawlet up to 0.2.10. This affects the function tools.webFetch of ...
CVE-2026-15619MEDIUM6.3A weakness has been identified in mosaxiv clawlet up to 0.2.10. The impacted element is the function web_fetch of the fi...
CVE-2026-15618MEDIUM6.3A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. The affected element is the function guardExecComma...
CVE-2026-58489MEDIUM6.8HedgeDoc is an open source, real-time collaborative markdown notes application. Prior to 1.11.0, the GitHub Gist export ...
CVE-2026-15607MEDIUM4.3A vulnerability was detected in tanstack db up to 0.6.8. Affected by this vulnerability is the function select of the fi...
CVE-2026-62239MEDIUM6.6FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and...
CVE-2026-62198MEDIUM5.4OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allo...
CVE-2026-62193MEDIUM6.5OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the in...
CVE-2026-58488MEDIUM6.9HedgeDoc is an open source, real-time, collaborative, markdown notes application. Versions prior to 1.11.0 allowed attac...
CVE-2026-58487MEDIUM5.1HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, due to unsafe...
CVE-2026-56877MEDIUM6.3The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026-07-13 does not validate the client-supplie...
CVE-2026-15682MEDIUM5.5AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to...
CVE-2026-15681MEDIUM5.5AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to cr...
CVE-2026-15598MEDIUM6.3A weakness has been identified in antv layout 2.0.0. This impacts the function setNestedValue in the library lib/util/ob...
CVE-2026-15596MEDIUM4.3A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unkno...
CVE-2026-15595MEDIUM4.3A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unkno...
CVE-2026-58408MEDIUM6.5ChurchCRM is an open-source church management system. Prior to version 7.4.0, a low-privileged user can bypass the /admi...
CVE-2026-12536MEDIUM6.4The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Module Title’ para...
CVE-2026-12385MEDIUM4.3The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now