2026 CVE Vulnerabilities
53,349 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24321 | MEDIUM | 5.3 | 0.2% | Feb 10, 2026 | SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these op... |
| CVE-2026-24319 | MEDIUM | 5.8 | 0.1% | Feb 10, 2026 | In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gainin... |
| CVE-2026-24312 | MEDIUM | 5.2 | 0.2% | Feb 10, 2026 | An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative... |
| CVE-2026-23688 | MEDIUM | 4.3 | 0.2% | Feb 10, 2026 | SAP Fiori App Manage Service Entry Sheets does not perform necessary authorization checks for an authenticated user, res... |
| CVE-2026-23685 | MEDIUM | 4.4 | 0.1% | Feb 10, 2026 | Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator wit... |
| CVE-2026-23684 | MEDIUM | 5.9 | 0.2% | Feb 10, 2026 | A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a car... |
| CVE-2026-23681 | MEDIUM | 4.3 | 0.2% | Feb 10, 2026 | Due to missing authorization check in a function module in SAP Support Tools Plug-In, an authenticated attacker could in... |
| CVE-2026-0505 | MEDIUM | 6.1 | 0.2% | Feb 10, 2026 | The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficientl... |
| CVE-2026-0486 | MEDIUM | 4.3 | 0.2% | Feb 10, 2026 | In ABAP based SAP systems a remote enabled function module does not perform necessary authorization checks for an authen... |
| CVE-2026-0484 | MEDIUM | 6.5 | 0.3% | Feb 10, 2026 | Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker c... |
| CVE-2026-2258 | MEDIUM | 5.5 | 0.2% | Feb 10, 2026 | A flaw has been found in aardappel lobster up to 2025.4. Affected by this vulnerability is the function WaveFunctionColl... |
| CVE-2026-25957 | MEDIUM | 6.5 | 0.4% | Feb 9, 2026 | Cube is a semantic layer for building data applications. From 1.1.17 to before 1.5.13 and 1.4.2, it is possible to make ... |
| CVE-2026-25934 | MEDIUM | 4.3 | 0.1% | Feb 9, 2026 | go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discov... |
| CVE-2026-25920 | MEDIUM | 5.5 | 0.2% | Feb 9, 2026 | SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, a heap out-of-bounds read vulnerability exists in... |
| CVE-2026-25918 | MEDIUM | 5.5 | 0.1% | Feb 9, 2026 | unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-agains... |
| CVE-2026-25889 | MEDIUM | 5.4 | 0.3% | Feb 9, 2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ... |
| CVE-2026-25878 | MEDIUM | 5.3 | 0.4% | Feb 9, 2026 | FroshAdminer is the Adminer plugin for Shopware Platform. Prior to 2.2.1, the Adminer route (/admin/adminer) was accessi... |
| CVE-2026-25806 | MEDIUM | 6.5 | 0.2% | Feb 9, 2026 | PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the GET /api/students/... |
| CVE-2026-25765 | MEDIUM | 5.8 | 0.4% | Feb 9, 2026 | Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1... |
| CVE-2026-25740 | MEDIUM | 5.8 | 0.1% | Feb 9, 2026 | captive browser, a dedicated Chrome instance to log into captive portals without messing with DNS settings. In 25.05 and... |
| CVE-2026-25528 | MEDIUM | 5.8 | 0.3% | Feb 9, 2026 | LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. The LangSmith SDK's distributed tracing... |
| CVE-2026-25598 | MEDIUM | 5.3 | 0.3% | Feb 9, 2026 | Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Prior to 2.14.2, a security v... |
| CVE-2026-25496 | MEDIUM | 4.8 | 0.4% | Feb 9, 2026 | Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through ... |
| CVE-2026-25494 | MEDIUM | 6.5 | 0.4% | Feb 9, 2026 | Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through... |
| CVE-2026-25493 | MEDIUM | 6.5 | 0.4% | Feb 9, 2026 | Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now