2026 CVE Vulnerabilities
48,546 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2300 | MEDIUM | 6.4 | 0.2% | May 12, 2026 | The BJ Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `filter_images()` function in... |
| CVE-2026-1681 | MEDIUM | 6.1 | 0.1% | May 12, 2026 | Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursi... |
| CVE-2026-41530 | MEDIUM | 4.6 | 0.1% | May 12, 2026 | The automatic folder creation feature of Lhaz and Lhaz+ provided by Chitora soft contains a path traversal vulnerability... |
| CVE-2026-7257 | MEDIUM | 4.4 | 0.1% | May 12, 2026 | ** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of ... |
| CVE-2026-7255 | MEDIUM | 6.5 | 0.2% | May 12, 2026 | ** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web ma... |
| CVE-2026-40137 | MEDIUM | 6.1 | 0.2% | May 12, 2026 | SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when ... |
| CVE-2026-40136 | MEDIUM | 4.3 | 0.3% | May 12, 2026 | SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions tem... |
| CVE-2026-40135 | MEDIUM | 6.5 | 1.4% | May 12, 2026 | An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that all... |
| CVE-2026-40134 | MEDIUM | 4.3 | 0.2% | May 12, 2026 | Due to insufficient authorization checks in the SAP Incentive and Commission Management application, authenticated users... |
| CVE-2026-40133 | MEDIUM | 6.3 | 0.2% | May 12, 2026 | Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthoriz... |
| CVE-2026-40132 | MEDIUM | 5.4 | 0.2% | May 12, 2026 | Due to missing authorization check in SAP Strategic Enterprise Management (Scorecard Wizard in Business Server Pages), a... |
| CVE-2026-40129 | MEDIUM | 4.3 | 0.3% | May 12, 2026 | Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticat... |
| CVE-2026-34258 | MEDIUM | 4.7 | 0.2% | May 12, 2026 | SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the Search UI to include ... |
| CVE-2026-27682 | MEDIUM | 6.1 | 0.2% | May 12, 2026 | Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based... |
| CVE-2026-0502 | MEDIUM | 5.4 | 0.1% | May 12, 2026 | Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could b... |
| CVE-2026-8349 | MEDIUM | 4.3 | 0.3% | May 12, 2026 | A flaw has been found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGAP Mes... |
| CVE-2026-43901 | MEDIUM | 6.8 | 0.3% | May 11, 2026 | Wireshark MCP is an MCP Server that turns tshark into a structured analysis interface, then layers in optional Wireshark... |
| CVE-2026-42554 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | Fiber is a web framework for Go. Prior to 2.52.12 and 3.1.0, Cross-Site Scripting vulnerability in Go Fiber allows a rem... |
| CVE-2026-34962 | MEDIUM | 5.5 | 0.1% | May 11, 2026 | barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_... |
| CVE-2026-7010 | MEDIUM | 6.5 | 0.2% | May 11, 2026 | HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values. Th... |
| CVE-2026-44695 | MEDIUM | 6.5 | 0.1% | May 11, 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET... |
| CVE-2026-43889 | MEDIUM | 6.5 | 0.2% | May 11, 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.7.0, the shares.create API accepts both col... |
| CVE-2026-43883 | MEDIUM | 4.2 | 0.2% | May 11, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/PayPalYPT/agreementCancel.jso... |
| CVE-2026-43882 | MEDIUM | 4.3 | 0.2% | May 11, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 29.0, the unauthenticated plugin/Scheduler... |
| CVE-2026-43881 | MEDIUM | 5.3 | 0.3% | May 11, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/users.json.php exposes two u... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now