2026 CVE Vulnerabilities
70,292 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3240 | MEDIUM | 4.8 | 0.2% | Mar 4, 2026 | In Concrete CMS below version 9.4.8, a user with permission to edit a page with element Legacy form can perform a stored... |
| CVE-2026-2994 | MEDIUM | 6.8 | 0.2% | Mar 4, 2026 | Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configu... |
| CVE-2026-3452 | HIGH | 7.2 | 0.6% | Mar 4, 2026 | Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express ... |
| CVE-2026-3244 | MEDIUM | 4.8 | 0.2% | Mar 4, 2026 | In Concrete CMS below version 9.4.8, A stored cross-site scripting (XSS) vulnerability exists in the search block where ... |
| CVE-2026-2292 | MEDIUM | 4.4 | 0.2% | Mar 4, 2026 | The Morkva UA Shipping plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi... |
| CVE-2026-2289 | MEDIUM | 4.4 | 0.3% | Mar 4, 2026 | The Taskbuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ... |
| CVE-2026-1980 | MEDIUM | 5.3 | 0.4% | Mar 4, 2026 | The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on ... |
| CVE-2026-1945 | HIGH | 7.2 | 0.3% | Mar 4, 2026 | The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_ema... |
| CVE-2026-1651 | MEDIUM | 6.5 | 0.4% | Mar 4, 2026 | The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the 'workflow_ids' para... |
| CVE-2026-1273 | HIGH | 7.2 | 0.3% | Mar 4, 2026 | The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Server-S... |
| CVE-2026-3266 | CRITICAL | 9.8 | 0.3% | Mar 3, 2026 | Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauth... |
| CVE-2026-3076 | — | — | — | Mar 3, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-2363. Reason: This candidate is a r... |
| CVE-2026-28289 | HIGH | 8.1 | 31.1% | Mar 3, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-... |
| CVE-2026-27981 | HIGH | 7.4 | 0.3% | Mar 3, 2026 | HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter) ... |
| CVE-2026-27971 | CRITICAL | 9.8 | 4.6% | Mar 3, 2026 | Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization ... |
| CVE-2026-27932 | HIGH | 7.5 | 0.4% | Mar 3, 2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar... |
| CVE-2026-27905 | HIGH | 7.8 | 0.2% | Mar 3, 2026 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.... |
| CVE-2026-27622 | HIGH | 7.8 | 0.2% | Mar 3, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-27601 | MEDIUM | 5.9 | 0.6% | Mar 3, 2026 | Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recur... |
| CVE-2026-27600 | MEDIUM | 4.3 | 0.2% | Mar 3, 2026 | HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, the notifier functionality allows authenticat... |
| CVE-2026-26279 | CRITICAL | 9.1 | 0.8% | Mar 3, 2026 | Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== ins... |
| CVE-2026-26272 | MEDIUM | 5.4 | 0.2% | Mar 3, 2026 | HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerabi... |
| CVE-2026-26266 | MEDIUM | 6.1 | 0.2% | Mar 3, 2026 | AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnera... |
| CVE-2026-25590 | MEDIUM | 6.1 | 0.2% | Mar 3, 2026 | The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents... |
| CVE-2026-3487 | HIGH | 7.2 | 0.4% | Mar 3, 2026 | A vulnerability was found in itsourcecode College Management System 1.0. This issue affects some unknown processing of t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now