2026 CVE Vulnerabilities

56,258 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-24322HIGH7.7SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks f...
CVE-2026-23689HIGH7.7Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular us...
CVE-2026-23687HIGH8.8SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtai...
CVE-2026-0508HIGH8.1The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert m...
CVE-2026-0490HIGH7.5SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted en...
CVE-2026-0485HIGH7.5SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause t...
CVE-2026-0845HIGH7.2The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is...
CVE-2026-25958HIGH7.7Cube is a semantic layer for building data applications. From 0.27.19 to before 1.5.13, 1.4.2, and 1.0.14, it is possibl...
CVE-2026-25951HIGH7.2FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path s...
CVE-2026-25931HIGH7.8vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings...
CVE-2026-25961HIGH7.5SumatraPDF is a multi-format reader for Windows. In 3.5.0 through 3.5.2, SumatraPDF's update mechanism disables TLS host...
CVE-2026-25925HIGH7.8PowerDocu contains a Windows GUI executable to perform technical documentations. Prior to 2.4.0, PowerDocu contains a cr...
CVE-2026-25892HIGH7.5Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where admi...
CVE-2026-25890HIGH8.1File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2026-25885HIGH7.5PolarLearn is a free and open-source learning program. In 0-PRERELEASE-16 and earlier, the group chat WebSocket at wss:/...
CVE-2026-25880HIGH7.8SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, the PDF reader allows execution of a malicious bi...
CVE-2026-25813HIGH7.5PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The application logs h...
CVE-2026-25812HIGH8.8PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application enable...
CVE-2026-25808HIGH7.5Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 an...
CVE-2026-25807HIGH8.8ZAI Shell is an autonomous SysOps agent designed to navigate, repair, and secure complex environments. Prior to 9.0.3, t...
CVE-2026-25791HIGH7.5Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener acc...
CVE-2026-25761HIGH8.8Super-linter is a combination of multiple linters to run as a GitHub Action or standalone. From 6.0.0 to 8.3.0, the Supe...
CVE-2026-25639HIGH7.5Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig f...
CVE-2026-25498HIGH7.2Craft is a platform for creating digital experiences. In versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21...
CVE-2026-25497HIGH8.8Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now