2026 CVE Vulnerabilities

56,998 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15629MEDIUM6.3A weakness has been identified in louisho5 picobot up to 0.2.0. Impacted is the function CreateSkill/GetSkill of the fil...
CVE-2026-15628MEDIUM6.3A security flaw has been discovered in zhayujie chatgpt-on-wechat CowAgent up to 2.1.1. This issue affects the function ...
CVE-2026-15627MEDIUM4.3A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This vulnerability affects the function h...
CVE-2026-15626MEDIUM6.3A vulnerability was determined in nextlevelbuilder GoClaw 3.13.3-beta.3. This affects the function writeFile of the file...
CVE-2026-7640MEDIUM6.4The WP Customer Area plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the `...
CVE-2026-15625MEDIUM6.3A vulnerability was found in nextlevelbuilder GoClaw 3.11.3. Affected by this issue is the function ExecApprovalManager....
CVE-2026-15624MEDIUM6.3A vulnerability has been found in nextlevelbuilder GoClaw 3.13.3-beta.3. Affected by this vulnerability is the function ...
CVE-2026-15622MEDIUM5.5A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor...
CVE-2026-11802MEDIUM5.3The FoodBook Lite - Online Food Ordering System plugin for WordPress is vulnerable to Missing Authorization in all versi...
CVE-2026-11390MEDIUM6.4The News Kit Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Site Logo Title ...
CVE-2026-58233HIGH7.6SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted a...
CVE-2026-44771MEDIUM4.3SAP S/4HANA Draft operation does not perform necessary authorization checks for an authenticated user, a restricted user...
CVE-2026-44770MEDIUM4.3SAP Create Single Payment does not perform necessary authorization checks for an authenticated user, a restricted user c...
CVE-2026-44769MEDIUM5.5SAP S/4HANA application Project Management (PPM-PRO) allows an attacker with high privileges to execute crafted database...
CVE-2026-44768MEDIUM4.1SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to...
CVE-2026-44767MEDIUM6.1setThemeRoot() failed to enforce the sap-allowed-theme-origins allowlist. An attacker-controlled absolute cross-origin U...
CVE-2026-44761CRITICAL9.1SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from samp...
CVE-2026-44760MEDIUM4.7Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SAP NetWeave...
CVE-2026-44759MEDIUM6.1SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The...
CVE-2026-44753LOW3.7SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produ...
CVE-2026-44752HIGH8.2SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted ...
CVE-2026-44747CRITICAL9.9SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management t...
CVE-2026-44745HIGH8.1SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurati...
CVE-2026-27690CRITICAL9.1Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially craf...
CVE-2026-15621MEDIUM5.3A vulnerability was detected in mosaxiv clawlet up to 0.2.10. This impacts the function read_file/write_file/edit_file o...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now