2026 CVE Vulnerabilities

64,678 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48233HIGH7.1Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/sit_incidents.php where the offset GET pa...
CVE-2026-48232HIGH7.1Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/fullsit_incidents.php where the offset GE...
CVE-2026-48231HIGH7.1Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in tables.php where the multiple POST parameters ...
CVE-2026-48230MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ticketsmdb_import.php that al...
CVE-2026-48229MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_i.php that allows auth...
CVE-2026-48228MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_w.php that allows aut...
CVE-2026-48227MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient.php that allows authe...
CVE-2026-48226MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in os_watch.php that allows auth...
CVE-2026-48225MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in landb.php that allows authent...
CVE-2026-48224MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics214.php that allows authen...
CVE-2026-48223MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213rr.php that allows auth...
CVE-2026-48222MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213.php that allows authen...
CVE-2026-48221MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205a.php that allows authe...
CVE-2026-48220MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205.php that allows authen...
CVE-2026-48219MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics202.php that allows authen...
CVE-2026-48218MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in icons/buttons/landb.php that ...
CVE-2026-48217MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in delete_module.php that allows...
CVE-2026-48216MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in db_loader.php that allows aut...
CVE-2026-48215MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in circle.php that allows authen...
CVE-2026-48214MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_nm.php that allows authen...
CVE-2026-39593MEDIUM6.5Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiting Incorrectly Configured Access Control Security...
CVE-2026-48213MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add.php that allows authentic...
CVE-2026-48207CRITICAL9.8Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented Deserializati...
CVE-2026-9089HIGH8.8The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and ...
CVE-2026-39531CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit W...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now