2026 CVE Vulnerabilities

48,546 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-2300MEDIUM6.4The BJ Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `filter_images()` function in...
CVE-2026-1681MEDIUM6.1Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursi...
CVE-2026-41530MEDIUM4.6The automatic folder creation feature of Lhaz and Lhaz+ provided by Chitora soft contains a path traversal vulnerability...
CVE-2026-7257MEDIUM4.4** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of ...
CVE-2026-7255MEDIUM6.5** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web ma...
CVE-2026-40137MEDIUM6.1SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when ...
CVE-2026-40136MEDIUM4.3SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions tem...
CVE-2026-40135MEDIUM6.5An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that all...
CVE-2026-40134MEDIUM4.3Due to insufficient authorization checks in the SAP Incentive and Commission Management application, authenticated users...
CVE-2026-40133MEDIUM6.3Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthoriz...
CVE-2026-40132MEDIUM5.4Due to missing authorization check in SAP Strategic Enterprise Management (Scorecard Wizard in Business Server Pages), a...
CVE-2026-40129MEDIUM4.3Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticat...
CVE-2026-34258MEDIUM4.7SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the Search UI to include ...
CVE-2026-27682MEDIUM6.1Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based...
CVE-2026-0502MEDIUM5.4Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could b...
CVE-2026-8349MEDIUM4.3A flaw has been found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGAP Mes...
CVE-2026-43901MEDIUM6.8Wireshark MCP is an MCP Server that turns tshark into a structured analysis interface, then layers in optional Wireshark...
CVE-2026-42554MEDIUM6.1Fiber is a web framework for Go. Prior to 2.52.12 and 3.1.0, Cross-Site Scripting vulnerability in Go Fiber allows a rem...
CVE-2026-34962MEDIUM5.5barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_...
CVE-2026-7010MEDIUM6.5HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values. Th...
CVE-2026-44695MEDIUM6.5Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET...
CVE-2026-43889MEDIUM6.5Outline is a service that allows for collaborative documentation. Prior to 1.7.0, the shares.create API accepts both col...
CVE-2026-43883MEDIUM4.2WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/PayPalYPT/agreementCancel.jso...
CVE-2026-43882MEDIUM4.3WWBN AVideo is an open source video platform. In versions up to and including 29.0, the unauthenticated plugin/Scheduler...
CVE-2026-43881MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/users.json.php exposes two u...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now