2026 CVE Vulnerabilities

53,349 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-24321MEDIUM5.3SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these op...
CVE-2026-24319MEDIUM5.8In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gainin...
CVE-2026-24312MEDIUM5.2An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative...
CVE-2026-23688MEDIUM4.3SAP Fiori App Manage Service Entry Sheets does not perform necessary authorization checks for an authenticated user, res...
CVE-2026-23685MEDIUM4.4Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator wit...
CVE-2026-23684MEDIUM5.9A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a car...
CVE-2026-23681MEDIUM4.3Due to missing authorization check in a function module in SAP Support Tools Plug-In, an authenticated attacker could in...
CVE-2026-0505MEDIUM6.1The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficientl...
CVE-2026-0486MEDIUM4.3In ABAP based SAP systems a remote enabled function module does not perform necessary authorization checks for an authen...
CVE-2026-0484MEDIUM6.5Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker c...
CVE-2026-2258MEDIUM5.5A flaw has been found in aardappel lobster up to 2025.4. Affected by this vulnerability is the function WaveFunctionColl...
CVE-2026-25957MEDIUM6.5Cube is a semantic layer for building data applications. From 1.1.17 to before 1.5.13 and 1.4.2, it is possible to make ...
CVE-2026-25934MEDIUM4.3go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discov...
CVE-2026-25920MEDIUM5.5SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, a heap out-of-bounds read vulnerability exists in...
CVE-2026-25918MEDIUM5.5unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-agains...
CVE-2026-25889MEDIUM5.4File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2026-25878MEDIUM5.3FroshAdminer is the Adminer plugin for Shopware Platform. Prior to 2.2.1, the Adminer route (/admin/adminer) was accessi...
CVE-2026-25806MEDIUM6.5PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the GET /api/students/...
CVE-2026-25765MEDIUM5.8Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1...
CVE-2026-25740MEDIUM5.8captive browser, a dedicated Chrome instance to log into captive portals without messing with DNS settings. In 25.05 and...
CVE-2026-25528MEDIUM5.8LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. The LangSmith SDK's distributed tracing...
CVE-2026-25598MEDIUM5.3Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Prior to 2.14.2, a security v...
CVE-2026-25496MEDIUM4.8Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through ...
CVE-2026-25494MEDIUM6.5Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through...
CVE-2026-25493MEDIUM6.5Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now