2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-58243HIGH8.8SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attack...
CVE-2026-58230HIGH7SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated att...
CVE-2026-44765HIGH7.3Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated...
CVE-2026-44764HIGH7.3Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated...
CVE-2026-44763HIGH7.6SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation...
CVE-2026-8718HIGH8.4tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, T...
CVE-2026-72915HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta...
CVE-2026-72914HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-be...
CVE-2026-73033HIGH7Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmi...
CVE-2026-73030HIGH8.1unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory func...
CVE-2026-72913HIGH7.3Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/wind...
CVE-2026-72910HIGH7.1ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, p...
CVE-2026-72909HIGH7.1ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayabl...
CVE-2026-72903HIGH8.1Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can retu...
CVE-2026-63622HIGH7.8A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploi...
CVE-2026-18982HIGH8.8A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in a...
CVE-2026-18951HIGH8.8A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly ag...
CVE-2026-18950HIGH8.8A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how Rol...
CVE-2026-18949HIGH8.8A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Ac...
CVE-2026-18947HIGH8.5A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental...
CVE-2026-18941HIGH7.7A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is...
CVE-2026-18621HIGH7.6A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security harde...
CVE-2026-18620HIGH7.1A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerab...
CVE-2026-18618HIGH7.5A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to kn...
CVE-2026-18617HIGH8.8A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the sp...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now