2026 CVE Vulnerabilities

65,293 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34225MEDIUM4.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.7.2 and be...
CVE-2026-39424MEDIUM4.7MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, the chat export feature is vulnerable ...
CVE-2026-39423MEDIUM5.4MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an Eval Injection vulnerability in...
CVE-2026-39422MEDIUM5.4MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS...
CVE-2026-39421HIGH7.4MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a sandbox escape vulnerability in ...
CVE-2026-39420HIGH7.4MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an incomplete sandbox protection mecha...
CVE-2026-39418HIGH7.4MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, sandbox network protection can be bypa...
CVE-2026-34264MEDIUM6.5During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due t...
CVE-2026-34262MEDIUM4.3Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer
CVE-2026-34261MEDIUM6.5Due to a missing authorization check in SAP Business Analytics and SAP Content Management, an authenticated user could m...
CVE-2026-34257MEDIUM6.1Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft ...
CVE-2026-34256HIGH7.1Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud and On-Premise), an authenticated attacke...
CVE-2026-40164HIGH7.5jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a ...
CVE-2026-39417MEDIUM5.5MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an incomplete fix for CVE-2025-539...
CVE-2026-34069MEDIUM5.3nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a...
CVE-2026-33948MEDIUM5.3jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability whe...
CVE-2026-27683MEDIUM4.1SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript pa...
CVE-2026-27681CRITICAL9.9Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authe...
CVE-2026-27679MEDIUM6.5Due to missing authorization checks in the SAP S/4HANA frontend OData Service (Manage Reference Structures), an attacker...
CVE-2026-27678MEDIUM6.5Due to missing authorization checks in the SAP S/4HANA backend OData Service (Manage Reference Structures), an attacker ...
CVE-2026-27677MEDIUM6.5Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Reference Equipment), an attacker could upd...
CVE-2026-27676MEDIUM4.3Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Technical Object Structures), an attacker c...
CVE-2026-27675LOW2SAP Landscape Transformation contains a vulnerability in an RFC-exposed function module that could allow a high privileg...
CVE-2026-27674MEDIUM6.1Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated att...
CVE-2026-27673MEDIUM4.9Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now