2026 CVE Vulnerabilities
53,618 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0883 | MEDIUM | 5.3 | 0.4% | Jan 13, 2026 | Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thun... |
| CVE-2026-0684 | MEDIUM | 4.3 | 0.3% | Jan 13, 2026 | The CP Image Store with Slideshow plugin for WordPress is vulnerable to authorization bypass in all versions up to, and ... |
| CVE-2026-0514 | MEDIUM | 6.1 | 0.2% | Jan 13, 2026 | Due to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a m... |
| CVE-2026-0513 | MEDIUM | 4.7 | 0.2% | Jan 13, 2026 | Due to an Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog), an unauthen... |
| CVE-2026-0503 | MEDIUM | 6.4 | 0.2% | Jan 13, 2026 | Due to missing authorization check in the SAP ERP Central Component (SAP ECC) and SAP S/4HANA (SAP EHS Management), an a... |
| CVE-2026-0499 | MEDIUM | 6.1 | 0.2% | Jan 13, 2026 | SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The... |
| CVE-2026-0497 | MEDIUM | 4.3 | 0.2% | Jan 13, 2026 | SAP Product Designer Web UI of Business Server Pages allows authenticated non-administrative users to access non-sensiti... |
| CVE-2026-0496 | MEDIUM | 6.6 | 0.2% | Jan 13, 2026 | SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including... |
| CVE-2026-0495 | MEDIUM | 5.1 | 0.1% | Jan 13, 2026 | SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arb... |
| CVE-2026-0494 | MEDIUM | 4.3 | 0.2% | Jan 13, 2026 | Under certain conditions SAP Fiori App Intercompany Balance Reconciliation application allows an attacker to access info... |
| CVE-2026-0493 | MEDIUM | 4.3 | 0.1% | Jan 13, 2026 | Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App Intercompany Balance Reconciliation an attacke... |
| CVE-2026-22813 | MEDIUM | 6.1 | 0.9% | Jan 12, 2026 | OpenCode is an open source AI coding agent. The markdown renderer used for LLM responses will insert arbitrary HTML into... |
| CVE-2026-22804 | MEDIUM | 4.7 | 0.2% | Jan 12, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0... |
| CVE-2026-22800 | MEDIUM | 4.5 | 0.1% | Jan 12, 2026 | PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. Prior to 4.10.0, Cross-Site Reque... |
| CVE-2026-22212 | MEDIUM | 4.8 | 0.1% | Jan 12, 2026 | TinyOS versions up to and including 2.1.2 contain a stack-based buffer overflow vulnerability in the mcp2200gpio utility... |
| CVE-2026-22798 | MEDIUM | 5 | 0.2% | Jan 12, 2026 | hermes is an implementation of the HERMES workflow to automatize software publication with rich metadata. From 0.8.1 to ... |
| CVE-2026-22772 | MEDIUM | 5.3 | 0.2% | Jan 12, 2026 | Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to ... |
| CVE-2026-22784 | MEDIUM | 4.3 | 0.2% | Jan 12, 2026 | Lychee is a free, open-source photo-management tool. Prior to 7.1.0, an authorization vulnerability exists in Lychee's a... |
| CVE-2026-22251 | MEDIUM | 5.5 | 0.1% | Jan 12, 2026 | wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API key... |
| CVE-2026-22250 | MEDIUM | 5.5 | 0.1% | Jan 12, 2026 | wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped fo... |
| CVE-2026-22050 | MEDIUM | 4.3 | 0.2% | Jan 12, 2026 | ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a ... |
| CVE-2026-22033 | MEDIUM | 5.4 | 0.2% | Jan 12, 2026 | Label Studio is a multi-type data labeling and annotation tool. In 1.22.0 and earlier, a persistent stored cross-site sc... |
| CVE-2026-0853 | MEDIUM | 6.9 | 0.3% | Jan 12, 2026 | Certain NVR models developed by A-Plus Video Technologies has a Sensitive Data Exposure vulnerability, allowing unauthen... |
| CVE-2026-0843 | MEDIUM | 6.3 | 0.2% | Jan 11, 2026 | A vulnerability has been found in jiujiujia/victor123/wxw850227 jjjfood and jjjshop_food up to 20260103. This vulnerabil... |
| CVE-2026-0842 | MEDIUM | 6.3 | 0.4% | Jan 11, 2026 | A flaw has been found in Flycatcher Toys smART Sketcher up to 2.0. This affects an unknown part of the component Bluetoo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now