2026 CVE Vulnerabilities
42,999 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-72599 | CRITICAL | 9.8 | — | Aug 11, 2026 | An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the ne... |
| CVE-2026-72550 | CRITICAL | 9.8 | — | Aug 11, 2026 | An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to ex... |
| CVE-2026-13738 | CRITICAL | 9.2 | — | Aug 11, 2026 | CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Soft... |
| CVE-2026-13737 | CRITICAL | 9.2 | — | Aug 11, 2026 | CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upg... |
| CVE-2026-58231 | CRITICAL | 10 | — | Aug 11, 2026 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially craf... |
| CVE-2026-10579 | CRITICAL | 9.8 | 0.4% | Aug 11, 2026 | A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no v... |
| CVE-2026-19516 | CRITICAL | 9.1 | 0.2% | Aug 11, 2026 | A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the graf... |
| CVE-2026-13716 | CRITICAL | 9.1 | 0.6% | Aug 11, 2026 | Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to u... |
| CVE-2026-19425 | CRITICAL | 9.8 | — | Aug 11, 2026 | Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated re... |
| CVE-2026-44758 | CRITICAL | 9.1 | 0.5% | Aug 11, 2026 | SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted... |
| CVE-2026-34265 | CRITICAL | 9.8 | 0.4% | Aug 11, 2026 | SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol pars... |
| CVE-2026-48161 | CRITICAL | 9.3 | 0.4% | Aug 10, 2026 | react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contain... |
| CVE-2026-72911 | CRITICAL | 9.9 | — | Aug 10, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_templat... |
| CVE-2026-72904 | CRITICAL | 9.3 | 0.3% | Aug 10, 2026 | Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file ... |
| CVE-2026-48160 | CRITICAL | 9.3 | 0.4% | Aug 10, 2026 | react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the defau... |
| CVE-2026-18948 | CRITICAL | 9.9 | 0.7% | Aug 10, 2026 | A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, whic... |
| CVE-2026-14450 | CRITICAL | 9.9 | 0.4% | Aug 10, 2026 | A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy... |
| CVE-2026-72902 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to... |
| CVE-2026-72901 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-pri... |
| CVE-2026-72886 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.u... |
| CVE-2026-72882 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can crea... |
| CVE-2026-72880 | CRITICAL | 9.9 | 0.3% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in pack... |
| CVE-2026-72879 | CRITICAL | 9.4 | 0.3% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in pa... |
| CVE-2026-72878 | CRITICAL | 9.6 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline c... |
| CVE-2026-72877 | CRITICAL | 9.6 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated w... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now