2026 CVE Vulnerabilities

70,292 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3240MEDIUM4.8In Concrete CMS below version 9.4.8, a user with permission to edit a page with element Legacy form can perform a stored...
CVE-2026-2994MEDIUM6.8Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configu...
CVE-2026-3452HIGH7.2Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express ...
CVE-2026-3244MEDIUM4.8In Concrete CMS below version 9.4.8, A stored cross-site scripting (XSS) vulnerability exists in the search block where ...
CVE-2026-2292MEDIUM4.4The Morkva UA Shipping plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi...
CVE-2026-2289MEDIUM4.4The Taskbuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ...
CVE-2026-1980MEDIUM5.3The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on ...
CVE-2026-1945HIGH7.2The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_ema...
CVE-2026-1651MEDIUM6.5The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the 'workflow_ids' para...
CVE-2026-1273HIGH7.2The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Server-S...
CVE-2026-3266CRITICAL9.8Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauth...
CVE-2026-3076——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-2363. Reason: This candidate is a r...
CVE-2026-28289HIGH8.1FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-...
CVE-2026-27981HIGH7.4HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter) ...
CVE-2026-27971CRITICAL9.8Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization ...
CVE-2026-27932HIGH7.5joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar...
CVE-2026-27905HIGH7.8BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4....
CVE-2026-27622HIGH7.8OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-27601MEDIUM5.9Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recur...
CVE-2026-27600MEDIUM4.3HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, the notifier functionality allows authenticat...
CVE-2026-26279CRITICAL9.1Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== ins...
CVE-2026-26272MEDIUM5.4HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerabi...
CVE-2026-26266MEDIUM6.1AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnera...
CVE-2026-25590MEDIUM6.1The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents...
CVE-2026-3487HIGH7.2A vulnerability was found in itsourcecode College Management System 1.0. This issue affects some unknown processing of t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now