2026 CVE Vulnerabilities

69,850 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-30913MEDIUM4.6Flarum is open-source forum software. When the flarum/nicknames extension is enabled, a registered user can set their ni...
CVE-2026-30887CRITICAL9.9OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members ...
CVE-2026-30885MEDIUM5.3WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns al...
CVE-2026-30870MEDIUM6.5PowerSync Service is the server-side component of the PowerSync sync engine. In version 1.20.0, when using new sync stre...
CVE-2026-30869CRITICAL9.8SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoin...
CVE-2026-30862CRITICAL9Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulne...
CVE-2026-2364HIGH7.3If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS Development System, a low pr...
CVE-2026-29773MEDIUM4.3Kubewarden is a policy engine for Kubernetes. Kubewarden cluster operators can grant permissions to users to deploy name...
CVE-2026-28513HIGH7.1Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, th...
CVE-2026-28512MEDIUM6.1Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. From 2.0.0 to befo...
CVE-2026-28281HIGH7.1InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF token...
CVE-2026-28267MEDIUM6.8Multiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwrit...
CVE-2026-27689HIGH7.7Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular us...
CVE-2026-27688MEDIUM5Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user p...
CVE-2026-27687MEDIUM5.8Due to missing authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal, a user with high privileges cou...
CVE-2026-27686MEDIUM5.9Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform un...
CVE-2026-27685CRITICAL9.1SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content...
CVE-2026-27684MEDIUM6.4SAP NetWeaver Feedback Notifications Service contains a SQL injection vulnerability that allows an authenticated attacke...
CVE-2026-24317MEDIUM5SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated ...
CVE-2026-24316MEDIUM6.4SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP reques...
CVE-2026-24313MEDIUM5SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks f...
CVE-2026-24311MEDIUM5.6The SAP Customer Checkout application exhibits certain design characteristics that involve locally storing operational d...
CVE-2026-24310MEDIUM4.3Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute...
CVE-2026-24309MEDIUM6.4Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute...
CVE-2026-1920MEDIUM5.3The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthoriz...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now