2026 CVE Vulnerabilities

47,550 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-19516CRITICAL9.1A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the graf...
CVE-2026-18348MEDIUM4.1Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst...
CVE-2026-14549MEDIUM4.3The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of ...
CVE-2026-14548MEDIUM6.5The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of ...
CVE-2026-13716CRITICAL9.1Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to u...
CVE-2026-12052MEDIUM5.2The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next/class/usbd_cdc_ncm....
CVE-2026-12051MEDIUM4.6The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer der...
CVE-2026-11894MEDIUM5.9The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the...
CVE-2026-19425CRITICAL9.8Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated re...
CVE-2026-16974MEDIUM6.4The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site ...
CVE-2026-11985LOW3.6On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choice, which defaults to...
CVE-2026-11893MEDIUM5.9The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetoo...
CVE-2026-8917HIGH8.4Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a ...
CVE-2026-24330MEDIUM6.5A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a mali...
CVE-2026-24329MEDIUM4.9A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload i...
CVE-2026-19424HIGH8.7Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated rem...
CVE-2026-66779MEDIUM6.3Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker co...
CVE-2026-66778MEDIUM5.3SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. A...
CVE-2026-66777MEDIUM5.9SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. D...
CVE-2026-66776MEDIUM5.9SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under spec...
CVE-2026-66775MEDIUM4.3SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthent...
CVE-2026-66774LOW3.7SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this ...
CVE-2026-66773MEDIUM5.9A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data i...
CVE-2026-66772MEDIUM4.3SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on cer...
CVE-2026-66771MEDIUM6.1SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted applicatio...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now