2026 CVE Vulnerabilities
50,404 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1607 | MEDIUM | 6.4 | 0.2% | Apr 14, 2026 | The Surbma | Booking.com Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `s... |
| CVE-2026-34984 | MEDIUM | 6.5 | 0.3% | Apr 14, 2026 | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete... |
| CVE-2026-39426 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS... |
| CVE-2026-39425 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS... |
| CVE-2026-34225 | MEDIUM | 4.3 | 0.2% | Apr 14, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.7.2 and be... |
| CVE-2026-39424 | MEDIUM | 4.7 | 0.4% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, the chat export feature is vulnerable ... |
| CVE-2026-39423 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an Eval Injection vulnerability in... |
| CVE-2026-39422 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS... |
| CVE-2026-34264 | MEDIUM | 6.5 | 0.3% | Apr 14, 2026 | During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due t... |
| CVE-2026-34262 | MEDIUM | 4.3 | 0.3% | Apr 14, 2026 | Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer |
| CVE-2026-34261 | MEDIUM | 6.5 | 0.2% | Apr 14, 2026 | Due to a missing authorization check in SAP Business Analytics and SAP Content Management, an authenticated user could m... |
| CVE-2026-34257 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft ... |
| CVE-2026-39417 | MEDIUM | 5.5 | 0.2% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an incomplete fix for CVE-2025-539... |
| CVE-2026-34069 | MEDIUM | 5.3 | 0.3% | Apr 14, 2026 | nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a... |
| CVE-2026-33948 | MEDIUM | 5.3 | 0.3% | Apr 14, 2026 | jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability whe... |
| CVE-2026-27683 | MEDIUM | 4.1 | 0.2% | Apr 14, 2026 | SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript pa... |
| CVE-2026-27679 | MEDIUM | 6.5 | 0.2% | Apr 14, 2026 | Due to missing authorization checks in the SAP S/4HANA frontend OData Service (Manage Reference Structures), an attacker... |
| CVE-2026-27678 | MEDIUM | 6.5 | 0.2% | Apr 14, 2026 | Due to missing authorization checks in the SAP S/4HANA backend OData Service (Manage Reference Structures), an attacker ... |
| CVE-2026-27677 | MEDIUM | 6.5 | 0.2% | Apr 14, 2026 | Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Reference Equipment), an attacker could upd... |
| CVE-2026-27676 | MEDIUM | 4.3 | 0.2% | Apr 14, 2026 | Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Technical Object Structures), an attacker c... |
| CVE-2026-27674 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated att... |
| CVE-2026-27673 | MEDIUM | 4.9 | 0.2% | Apr 14, 2026 | Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete ... |
| CVE-2026-27672 | MEDIUM | 4.3 | 0.2% | Apr 14, 2026 | The Material Master application does not enforce authorization checks for authenticated users when executing reports, re... |
| CVE-2026-24318 | MEDIUM | 4.2 | 0.2% | Apr 14, 2026 | Due to an Insecure session management vulnerability in SAP Business Objects Business Intelligence Platform, an unauthent... |
| CVE-2026-0512 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management (SICF Handler in SRM Catal... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now