2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-27688MEDIUM5Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user p...
CVE-2026-27687MEDIUM5.8Due to missing authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal, a user with high privileges cou...
CVE-2026-27686MEDIUM5.9Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform un...
CVE-2026-27684MEDIUM6.4SAP NetWeaver Feedback Notifications Service contains a SQL injection vulnerability that allows an authenticated attacke...
CVE-2026-24317MEDIUM5SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated ...
CVE-2026-24316MEDIUM6.4SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP reques...
CVE-2026-24313MEDIUM5SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks f...
CVE-2026-24311MEDIUM5.6The SAP Customer Checkout application exhibits certain design characteristics that involve locally storing operational d...
CVE-2026-24310MEDIUM4.3Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute...
CVE-2026-24309MEDIUM6.4Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute...
CVE-2026-1920MEDIUM5.3The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthoriz...
CVE-2026-1919MEDIUM5.3The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthoriz...
CVE-2026-1508MEDIUM4.3The Court Reservation WordPress plugin before 1.10.9 does not have CSRF check in place when deleting events, which coul...
CVE-2026-0489MEDIUM6.1Due to insufficient validation of user-controlled input in the URLs query parameter. SAP Business One Job Service could ...
CVE-2026-31802MEDIUM5.5node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink t...
CVE-2026-30937MEDIUM6.1ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-30936MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-30935MEDIUM4.4ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28692MEDIUM4.8ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28690MEDIUM6.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28689MEDIUM6.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28688MEDIUM5.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28687MEDIUM5.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28686MEDIUM6.8ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28493MEDIUM6.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now