2026 CVE Vulnerabilities

53,618 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-0883MEDIUM5.3Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thun...
CVE-2026-0684MEDIUM4.3The CP Image Store with Slideshow plugin for WordPress is vulnerable to authorization bypass in all versions up to, and ...
CVE-2026-0514MEDIUM6.1Due to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a m...
CVE-2026-0513MEDIUM4.7Due to an Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog), an unauthen...
CVE-2026-0503MEDIUM6.4Due to missing authorization check in the SAP ERP Central Component (SAP ECC) and SAP S/4HANA (SAP EHS Management), an a...
CVE-2026-0499MEDIUM6.1SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The...
CVE-2026-0497MEDIUM4.3SAP Product Designer Web UI of Business Server Pages allows authenticated non-administrative users to access non-sensiti...
CVE-2026-0496MEDIUM6.6SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including...
CVE-2026-0495MEDIUM5.1SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arb...
CVE-2026-0494MEDIUM4.3Under certain conditions SAP Fiori App Intercompany Balance Reconciliation application allows an attacker to access info...
CVE-2026-0493MEDIUM4.3Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App Intercompany Balance Reconciliation an attacke...
CVE-2026-22813MEDIUM6.1OpenCode is an open source AI coding agent. The markdown renderer used for LLM responses will insert arbitrary HTML into...
CVE-2026-22804MEDIUM4.7Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0...
CVE-2026-22800MEDIUM4.5PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. Prior to 4.10.0, Cross-Site Reque...
CVE-2026-22212MEDIUM4.8TinyOS versions up to and including 2.1.2 contain a stack-based buffer overflow vulnerability in the mcp2200gpio utility...
CVE-2026-22798MEDIUM5hermes is an implementation of the HERMES workflow to automatize software publication with rich metadata. From 0.8.1 to ...
CVE-2026-22772MEDIUM5.3Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to ...
CVE-2026-22784MEDIUM4.3Lychee is a free, open-source photo-management tool. Prior to 7.1.0, an authorization vulnerability exists in Lychee's a...
CVE-2026-22251MEDIUM5.5wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API key...
CVE-2026-22250MEDIUM5.5wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped fo...
CVE-2026-22050MEDIUM4.3ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a ...
CVE-2026-22033MEDIUM5.4Label Studio is a multi-type data labeling and annotation tool. In 1.22.0 and earlier, a persistent stored cross-site sc...
CVE-2026-0853MEDIUM6.9Certain NVR models developed by A-Plus Video Technologies has a Sensitive Data Exposure vulnerability, allowing unauthen...
CVE-2026-0843MEDIUM6.3A vulnerability has been found in jiujiujia/victor123/wxw850227 jjjfood and jjjshop_food up to 20260103. This vulnerabil...
CVE-2026-0842MEDIUM6.3A flaw has been found in Flycatcher Toys smART Sketcher up to 2.0. This affects an unknown part of the component Bluetoo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now