2026 CVE Vulnerabilities
43,347 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14548 | MEDIUM | 6.5 | 0.1% | Aug 11, 2026 | The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of ... |
| CVE-2026-13716 | CRITICAL | 9.1 | 0.6% | Aug 11, 2026 | Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to u... |
| CVE-2026-12052 | MEDIUM | 5.2 | 0.2% | Aug 11, 2026 | The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next/class/usbd_cdc_ncm.... |
| CVE-2026-12051 | MEDIUM | 4.6 | 0.2% | Aug 11, 2026 | The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer der... |
| CVE-2026-11894 | MEDIUM | 5.9 | 0.2% | Aug 11, 2026 | The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the... |
| CVE-2026-19425 | CRITICAL | 9.8 | 0.5% | Aug 11, 2026 | Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated re... |
| CVE-2026-16974 | MEDIUM | 6.4 | 0.2% | Aug 11, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site ... |
| CVE-2026-11985 | LOW | 3.6 | 0.1% | Aug 11, 2026 | On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choice, which defaults to... |
| CVE-2026-11893 | MEDIUM | 5.9 | 0.2% | Aug 11, 2026 | The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetoo... |
| CVE-2026-8917 | HIGH | 8.4 | 0.1% | Aug 11, 2026 | Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a ... |
| CVE-2026-24330 | MEDIUM | 6.5 | 0.3% | Aug 11, 2026 | A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a mali... |
| CVE-2026-24329 | MEDIUM | 4.9 | 0.3% | Aug 11, 2026 | A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload i... |
| CVE-2026-19424 | HIGH | 8.7 | 0.4% | Aug 11, 2026 | Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated rem... |
| CVE-2026-66779 | MEDIUM | 6.3 | 0.2% | Aug 11, 2026 | Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker co... |
| CVE-2026-66778 | MEDIUM | 5.3 | 0.2% | Aug 11, 2026 | SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. A... |
| CVE-2026-66777 | MEDIUM | 5.9 | 0.3% | Aug 11, 2026 | SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. D... |
| CVE-2026-66776 | MEDIUM | 5.9 | 0.1% | Aug 11, 2026 | SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under spec... |
| CVE-2026-66775 | MEDIUM | 4.3 | 0.1% | Aug 11, 2026 | SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthent... |
| CVE-2026-66774 | LOW | 3.7 | 0.2% | Aug 11, 2026 | SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this ... |
| CVE-2026-66773 | MEDIUM | 5.9 | 0.2% | Aug 11, 2026 | A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data i... |
| CVE-2026-66772 | MEDIUM | 4.3 | 0.2% | Aug 11, 2026 | SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on cer... |
| CVE-2026-66771 | MEDIUM | 6.1 | 0.2% | Aug 11, 2026 | SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted applicatio... |
| CVE-2026-66770 | MEDIUM | 6.3 | 0.2% | Aug 11, 2026 | Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL... |
| CVE-2026-66764 | MEDIUM | 4.3 | 0.2% | Aug 11, 2026 | Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated user... |
| CVE-2026-66763 | HIGH | 7.9 | 0.1% | Aug 11, 2026 | SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects usi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now