2026 CVE Vulnerabilities
56,258 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24322 | HIGH | 7.7 | 0.2% | Feb 10, 2026 | SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks f... |
| CVE-2026-23689 | HIGH | 7.7 | 0.4% | Feb 10, 2026 | Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular us... |
| CVE-2026-23687 | HIGH | 8.8 | 0.5% | Feb 10, 2026 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtai... |
| CVE-2026-0508 | HIGH | 8.1 | 0.3% | Feb 10, 2026 | The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert m... |
| CVE-2026-0490 | HIGH | 7.5 | 0.4% | Feb 10, 2026 | SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted en... |
| CVE-2026-0485 | HIGH | 7.5 | 0.4% | Feb 10, 2026 | SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause t... |
| CVE-2026-0845 | HIGH | 7.2 | 0.4% | Feb 10, 2026 | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is... |
| CVE-2026-25958 | HIGH | 7.7 | 0.4% | Feb 9, 2026 | Cube is a semantic layer for building data applications. From 0.27.19 to before 1.5.13, 1.4.2, and 1.0.14, it is possibl... |
| CVE-2026-25951 | HIGH | 7.2 | 1.2% | Feb 9, 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path s... |
| CVE-2026-25931 | HIGH | 7.8 | 0.1% | Feb 9, 2026 | vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings... |
| CVE-2026-25961 | HIGH | 7.5 | 0.4% | Feb 9, 2026 | SumatraPDF is a multi-format reader for Windows. In 3.5.0 through 3.5.2, SumatraPDF's update mechanism disables TLS host... |
| CVE-2026-25925 | HIGH | 7.8 | 0.3% | Feb 9, 2026 | PowerDocu contains a Windows GUI executable to perform technical documentations. Prior to 2.4.0, PowerDocu contains a cr... |
| CVE-2026-25892 | HIGH | 7.5 | 1.6% | Feb 9, 2026 | Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where admi... |
| CVE-2026-25890 | HIGH | 8.1 | 0.5% | Feb 9, 2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ... |
| CVE-2026-25885 | HIGH | 7.5 | 0.3% | Feb 9, 2026 | PolarLearn is a free and open-source learning program. In 0-PRERELEASE-16 and earlier, the group chat WebSocket at wss:/... |
| CVE-2026-25880 | HIGH | 7.8 | 0.2% | Feb 9, 2026 | SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, the PDF reader allows execution of a malicious bi... |
| CVE-2026-25813 | HIGH | 7.5 | 0.3% | Feb 9, 2026 | PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The application logs h... |
| CVE-2026-25812 | HIGH | 8.8 | 0.1% | Feb 9, 2026 | PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application enable... |
| CVE-2026-25808 | HIGH | 7.5 | 0.4% | Feb 9, 2026 | Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 an... |
| CVE-2026-25807 | HIGH | 8.8 | 0.6% | Feb 9, 2026 | ZAI Shell is an autonomous SysOps agent designed to navigate, repair, and secure complex environments. Prior to 9.0.3, t... |
| CVE-2026-25791 | HIGH | 7.5 | 0.4% | Feb 9, 2026 | Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener acc... |
| CVE-2026-25761 | HIGH | 8.8 | 1.3% | Feb 9, 2026 | Super-linter is a combination of multiple linters to run as a GitHub Action or standalone. From 6.0.0 to 8.3.0, the Supe... |
| CVE-2026-25639 | HIGH | 7.5 | 2.8% | Feb 9, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig f... |
| CVE-2026-25498 | HIGH | 7.2 | 1.0% | Feb 9, 2026 | Craft is a platform for creating digital experiences. In versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21... |
| CVE-2026-25497 | HIGH | 8.8 | 0.4% | Feb 9, 2026 | Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now