2026 CVE Vulnerabilities
65,293 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34225 | MEDIUM | 4.3 | 0.2% | Apr 14, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.7.2 and be... |
| CVE-2026-39424 | MEDIUM | 4.7 | 0.4% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, the chat export feature is vulnerable ... |
| CVE-2026-39423 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an Eval Injection vulnerability in... |
| CVE-2026-39422 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS... |
| CVE-2026-39421 | HIGH | 7.4 | 0.3% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a sandbox escape vulnerability in ... |
| CVE-2026-39420 | HIGH | 7.4 | 0.5% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an incomplete sandbox protection mecha... |
| CVE-2026-39418 | HIGH | 7.4 | 0.2% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, sandbox network protection can be bypa... |
| CVE-2026-34264 | MEDIUM | 6.5 | 0.3% | Apr 14, 2026 | During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due t... |
| CVE-2026-34262 | MEDIUM | 4.3 | 0.3% | Apr 14, 2026 | Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer |
| CVE-2026-34261 | MEDIUM | 6.5 | 0.2% | Apr 14, 2026 | Due to a missing authorization check in SAP Business Analytics and SAP Content Management, an authenticated user could m... |
| CVE-2026-34257 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft ... |
| CVE-2026-34256 | HIGH | 7.1 | 0.2% | Apr 14, 2026 | Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud and On-Premise), an authenticated attacke... |
| CVE-2026-40164 | HIGH | 7.5 | 0.4% | Apr 14, 2026 | jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a ... |
| CVE-2026-39417 | MEDIUM | 5.5 | 0.2% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an incomplete fix for CVE-2025-539... |
| CVE-2026-34069 | MEDIUM | 5.3 | 0.3% | Apr 14, 2026 | nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a... |
| CVE-2026-33948 | MEDIUM | 5.3 | 0.3% | Apr 14, 2026 | jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability whe... |
| CVE-2026-27683 | MEDIUM | 4.1 | 0.2% | Apr 14, 2026 | SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript pa... |
| CVE-2026-27681 | CRITICAL | 9.9 | 0.5% | Apr 14, 2026 | Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authe... |
| CVE-2026-27679 | MEDIUM | 6.5 | 0.2% | Apr 14, 2026 | Due to missing authorization checks in the SAP S/4HANA frontend OData Service (Manage Reference Structures), an attacker... |
| CVE-2026-27678 | MEDIUM | 6.5 | 0.2% | Apr 14, 2026 | Due to missing authorization checks in the SAP S/4HANA backend OData Service (Manage Reference Structures), an attacker ... |
| CVE-2026-27677 | MEDIUM | 6.5 | 0.2% | Apr 14, 2026 | Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Reference Equipment), an attacker could upd... |
| CVE-2026-27676 | MEDIUM | 4.3 | 0.2% | Apr 14, 2026 | Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Technical Object Structures), an attacker c... |
| CVE-2026-27675 | LOW | 2 | 0.2% | Apr 14, 2026 | SAP Landscape Transformation contains a vulnerability in an RFC-exposed function module that could allow a high privileg... |
| CVE-2026-27674 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated att... |
| CVE-2026-27673 | MEDIUM | 4.9 | 0.2% | Apr 14, 2026 | Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now