2026 CVE Vulnerabilities

64,659 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8352——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-8350HIGH8.8Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to pr...
CVE-2026-8205MEDIUM5.3Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since action_get_events does no...
CVE-2026-8204MEDIUM5.3Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow...
CVE-2026-8203MEDIUM5.4Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $heigh...
CVE-2026-8197MEDIUM4.8Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration name. The OAuth authorize template render...
CVE-2026-8140MEDIUM6.5Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/install/down...
CVE-2026-8135HIGH7.2Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the Ex...
CVE-2026-8134HIGH7.2Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTempl...
CVE-2026-6826MEDIUM5.3Concrete CMS 9.5.0 and below  is vulnerable to unauthenticated file usage disclosure via missing permission check in the...
CVE-2026-47102HIGH8.8LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint c...
CVE-2026-47101HIGH8.8LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role ...
CVE-2026-4843MEDIUM4.3The GSheet For Woo Importer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability ...
CVE-2026-47114HIGH8.8IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote attackers to execute arbit...
CVE-2026-46473HIGH7.5Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand. Secrets were generated using Perl's built-in r...
CVE-2026-48249HIGH8.2Open ISES Tickets before 3.44.2 disables TLS certificate verification in rm/incs/mobile_login.inc.php by setting CURLOPT...
CVE-2026-48248HIGH8.2Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/login.inc.php by setting CURLOPT_SSL_VERIF...
CVE-2026-48247HIGH8.2Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/functions.inc.php by setting CURLOPT_SSL_V...
CVE-2026-48246HIGH8.2Open ISES Tickets before 3.44.2 disables TLS certificate verification in ajax/reports.php by setting CURLOPT_SSL_VERIFYP...
CVE-2026-48245MEDIUM6.9Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in tables.php that is committed to the public sou...
CVE-2026-48244MEDIUM6.9Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that is committed to the publ...
CVE-2026-48243MEDIUM6.9Open ISES Tickets before 3.44.2 embeds a hardcoded WhitePages reverse-phone API key in wp1.php that is committed to the ...
CVE-2026-48242CRITICAL9.2Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, username, password, data...
CVE-2026-48241CRITICAL9.2Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database ut...
CVE-2026-48240HIGH7.1Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/statistics.php where the tick_id and f_ti...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now