2026 CVE Vulnerabilities

50,952 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-8417HIGH8.8Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/do_up...
CVE-2026-8350HIGH8.8Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to pr...
CVE-2026-8135HIGH7.2Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the Ex...
CVE-2026-8134HIGH7.2Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTempl...
CVE-2026-47102HIGH8.8LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint c...
CVE-2026-47101HIGH8.8LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role ...
CVE-2026-47114HIGH8.8IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote attackers to execute arbit...
CVE-2026-46473HIGH7.5Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand. Secrets were generated using Perl's built-in r...
CVE-2026-48249HIGH8.2Open ISES Tickets before 3.44.2 disables TLS certificate verification in rm/incs/mobile_login.inc.php by setting CURLOPT...
CVE-2026-48248HIGH8.2Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/login.inc.php by setting CURLOPT_SSL_VERIF...
CVE-2026-48247HIGH8.2Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/functions.inc.php by setting CURLOPT_SSL_V...
CVE-2026-48246HIGH8.2Open ISES Tickets before 3.44.2 disables TLS certificate verification in ajax/reports.php by setting CURLOPT_SSL_VERIFYP...
CVE-2026-48240HIGH7.1Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/statistics.php where the tick_id and f_ti...
CVE-2026-48239HIGH7.1Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/reports.php where the tick_id POST parame...
CVE-2026-48238HIGH7.1Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/mobile_main.php where the id GET paramete...
CVE-2026-48237HIGH7.1Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in message.php where the frm_ticket_id and frm_re...
CVE-2026-48236HIGH7.1Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in db_loader.php where the multiple POST paramete...
CVE-2026-48235HIGH8.8Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in incs/remotes.inc.php where latitude, longitude...
CVE-2026-48234HIGH7.1Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in portal/ajax/list_requests.php where the sort a...
CVE-2026-48233HIGH7.1Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/sit_incidents.php where the offset GET pa...
CVE-2026-48232HIGH7.1Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/fullsit_incidents.php where the offset GE...
CVE-2026-48231HIGH7.1Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in tables.php where the multiple POST parameters ...
CVE-2026-9089HIGH8.8The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and ...
CVE-2026-45208HIGH7.8A time-of-check time-of-use vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges ...
CVE-2026-45207HIGH7.8An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now