2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-0541HIGH7.3ACAP applications can gain elevated privileges due to improper input validation during the installation process, potenti...
CVE-2026-41872CRITICAL9.1"Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle at...
CVE-2026-41530MEDIUM4.6The automatic folder creation feature of Lhaz and Lhaz+ provided by Chitora soft contains a path traversal vulnerability...
CVE-2026-7287HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formU...
CVE-2026-7257MEDIUM4.4** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of ...
CVE-2026-7256HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware versio...
CVE-2026-7255MEDIUM6.5** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web ma...
CVE-2026-45430HIGH7.1The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect the au...
CVE-2026-40137MEDIUM6.1SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when ...
CVE-2026-40136MEDIUM4.3SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions tem...
CVE-2026-40135MEDIUM6.5An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that all...
CVE-2026-40134MEDIUM4.3Due to insufficient authorization checks in the SAP Incentive and Commission Management application, authenticated users...
CVE-2026-40133MEDIUM6.3Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthoriz...
CVE-2026-40132MEDIUM5.4Due to missing authorization check in SAP Strategic Enterprise Management (Scorecard Wizard in Business Server Pages), a...
CVE-2026-40131LOW3.4SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user ...
CVE-2026-40129MEDIUM4.3Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticat...
CVE-2026-34263CRITICAL9.6Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious in...
CVE-2026-34260CRITICAL9.6SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacke...
CVE-2026-34259HIGH8.2Due to an OS Command Execution vulnerability in SAP Forecasting & Replenishment, an authenticated attacker with administ...
CVE-2026-34258MEDIUM4.7SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the Search UI to include ...
CVE-2026-27682MEDIUM6.1Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based...
CVE-2026-0502MEDIUM5.4Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could b...
CVE-2026-45393HIGH8.5A vulnerability chain in Cribl Edge for Windows before 4.17.1 allows a local authenticated user to escalate privileges t...
CVE-2026-45392HIGH8.7DOM-based cross-site scripting (XSS) in Cribl Stream before 4.17.1 allows a remote attacker to execute arbitrary JavaScr...
CVE-2026-45391HIGH8.5A command injection vulnerability in Cribl Edge for Linux versions 3.2.0 through 4.17.0 allows a local unprivileged user...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now