2026 CVE Vulnerabilities

43,246 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-66779MEDIUM6.3Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker co...
CVE-2026-66778MEDIUM5.3SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. A...
CVE-2026-66777MEDIUM5.9SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. D...
CVE-2026-66776MEDIUM5.9SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under spec...
CVE-2026-66775MEDIUM4.3SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthent...
CVE-2026-66773MEDIUM5.9A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data i...
CVE-2026-66772MEDIUM4.3SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on cer...
CVE-2026-66771MEDIUM6.1SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted applicatio...
CVE-2026-66770MEDIUM6.3Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL...
CVE-2026-66764MEDIUM4.3Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated user...
CVE-2026-66761MEDIUM4.3SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could s...
CVE-2026-66760MEDIUM6.4SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges...
CVE-2026-58248MEDIUM6.5SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a speci...
CVE-2026-58247MEDIUM5.3SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This coul...
CVE-2026-58244MEDIUM4.3SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain applicati...
CVE-2026-58241MEDIUM4.2SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privi...
CVE-2026-58238MEDIUM5.9SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could...
CVE-2026-58237MEDIUM5.9WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with l...
CVE-2026-58236MEDIUM5.5SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing securit...
CVE-2026-58235MEDIUM6.3SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer...
CVE-2026-40130MEDIUM5.3SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated atta...
CVE-2026-72919MEDIUM4.3Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7...
CVE-2026-72918MEDIUM5.4Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7...
CVE-2026-72917MEDIUM5.9AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-72916MEDIUM6.3Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-be...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now