2026 CVE Vulnerabilities

47,130 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-41844MEDIUM6.1A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly sp...
CVE-2026-41843MEDIUM5.9Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected ...
CVE-2026-41841MEDIUM5.9Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. A...
CVE-2026-41840MEDIUM5.9Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affect...
CVE-2026-41839MEDIUM4.2A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerab...
CVE-2026-41715MEDIUM6.1In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may ...
CVE-2026-41710MEDIUM5.9An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the applicati...
CVE-2026-11623MEDIUM4.5A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c. ...
CVE-2026-11603MEDIUM6.1The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'args[f...
CVE-2026-10738MEDIUM6.4The jQuery Hover Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Footnote Qualifier ('{{...
CVE-2026-10553MEDIUM4.3The jQuery Hover Footnotes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2026-10024MEDIUM6.4The TinyMCE shortcode Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'btnrel' Shortcode Att...
CVE-2026-5714MEDIUM6.4The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘location_dir’ parame...
CVE-2026-11621MEDIUM4.7A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /adm...
CVE-2026-11620MEDIUM5.5A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsf...
CVE-2026-11619MEDIUM6.3A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file...
CVE-2026-10862MEDIUM6.4The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all ver...
CVE-2026-44757MEDIUM4.7SAP Wily Introscope Enterprise Manager allows an unauthenticated attacker to craft a specially crafted URL. Under certai...
CVE-2026-44755MEDIUM4.3SAP Business Objects Business Intelligence Platform does not sufficiently validate email sending parameters supplied by ...
CVE-2026-44754MEDIUM6.6The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (ODP-RFC) are missing c...
CVE-2026-44750MEDIUM4.3SAP MDG (Review Match Groups Application) does not perform the necessary authorization checks for authenticated users. T...
CVE-2026-44746MEDIUM6.1Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticate...
CVE-2026-44744MEDIUM6.5SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module component that could be...
CVE-2026-24315MEDIUM4.2SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, ...
CVE-2026-11701MEDIUM5.4Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now