2026 CVE Vulnerabilities
64,678 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48233 | HIGH | 7.1 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/sit_incidents.php where the offset GET pa... |
| CVE-2026-48232 | HIGH | 7.1 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/fullsit_incidents.php where the offset GE... |
| CVE-2026-48231 | HIGH | 7.1 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in tables.php where the multiple POST parameters ... |
| CVE-2026-48230 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ticketsmdb_import.php that al... |
| CVE-2026-48229 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_i.php that allows auth... |
| CVE-2026-48228 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_w.php that allows aut... |
| CVE-2026-48227 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient.php that allows authe... |
| CVE-2026-48226 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in os_watch.php that allows auth... |
| CVE-2026-48225 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in landb.php that allows authent... |
| CVE-2026-48224 | MEDIUM | 5.4 | 0.3% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics214.php that allows authen... |
| CVE-2026-48223 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213rr.php that allows auth... |
| CVE-2026-48222 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213.php that allows authen... |
| CVE-2026-48221 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205a.php that allows authe... |
| CVE-2026-48220 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205.php that allows authen... |
| CVE-2026-48219 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics202.php that allows authen... |
| CVE-2026-48218 | MEDIUM | 5.4 | 0.3% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in icons/buttons/landb.php that ... |
| CVE-2026-48217 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in delete_module.php that allows... |
| CVE-2026-48216 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in db_loader.php that allows aut... |
| CVE-2026-48215 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in circle.php that allows authen... |
| CVE-2026-48214 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_nm.php that allows authen... |
| CVE-2026-39593 | MEDIUM | 6.5 | 0.3% | May 21, 2026 | Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiting Incorrectly Configured Access Control Security... |
| CVE-2026-48213 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add.php that allows authentic... |
| CVE-2026-48207 | CRITICAL | 9.8 | 0.6% | May 21, 2026 | Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented Deserializati... |
| CVE-2026-9089 | HIGH | 8.8 | 0.3% | May 21, 2026 | The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and ... |
| CVE-2026-39531 | CRITICAL | 9.3 | 0.2% | May 21, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit W... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now