2026 CVE Vulnerabilities

50,404 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-1607MEDIUM6.4The Surbma | Booking.com Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `s...
CVE-2026-34984MEDIUM6.5External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete...
CVE-2026-39426MEDIUM5.4MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS...
CVE-2026-39425MEDIUM5.4MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS...
CVE-2026-34225MEDIUM4.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.7.2 and be...
CVE-2026-39424MEDIUM4.7MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, the chat export feature is vulnerable ...
CVE-2026-39423MEDIUM5.4MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an Eval Injection vulnerability in...
CVE-2026-39422MEDIUM5.4MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS...
CVE-2026-34264MEDIUM6.5During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due t...
CVE-2026-34262MEDIUM4.3Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer
CVE-2026-34261MEDIUM6.5Due to a missing authorization check in SAP Business Analytics and SAP Content Management, an authenticated user could m...
CVE-2026-34257MEDIUM6.1Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft ...
CVE-2026-39417MEDIUM5.5MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an incomplete fix for CVE-2025-539...
CVE-2026-34069MEDIUM5.3nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a...
CVE-2026-33948MEDIUM5.3jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability whe...
CVE-2026-27683MEDIUM4.1SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript pa...
CVE-2026-27679MEDIUM6.5Due to missing authorization checks in the SAP S/4HANA frontend OData Service (Manage Reference Structures), an attacker...
CVE-2026-27678MEDIUM6.5Due to missing authorization checks in the SAP S/4HANA backend OData Service (Manage Reference Structures), an attacker ...
CVE-2026-27677MEDIUM6.5Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Reference Equipment), an attacker could upd...
CVE-2026-27676MEDIUM4.3Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Technical Object Structures), an attacker c...
CVE-2026-27674MEDIUM6.1Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated att...
CVE-2026-27673MEDIUM4.9Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete ...
CVE-2026-27672MEDIUM4.3The Material Master application does not enforce authorization checks for authenticated users when executing reports, re...
CVE-2026-24318MEDIUM4.2Due to an Insecure session management vulnerability in SAP Business Objects Business Intelligence Platform, an unauthent...
CVE-2026-0512MEDIUM6.1Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management (SICF Handler in SRM Catal...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now