2026 CVE Vulnerabilities
52,659 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1919 | MEDIUM | 5.3 | 0.3% | Mar 10, 2026 | The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthoriz... |
| CVE-2026-1508 | MEDIUM | 4.3 | 0.1% | Mar 10, 2026 | The Court Reservation WordPress plugin before 1.10.9 does not have CSRF check in place when deleting events, which coul... |
| CVE-2026-0489 | MEDIUM | 6.1 | 0.2% | Mar 10, 2026 | Due to insufficient validation of user-controlled input in the URLs query parameter. SAP Business One Job Service could ... |
| CVE-2026-31802 | MEDIUM | 5.5 | 0.3% | Mar 10, 2026 | node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink t... |
| CVE-2026-30937 | MEDIUM | 6.1 | 0.1% | Mar 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1... |
| CVE-2026-30936 | MEDIUM | 5.5 | 0.1% | Mar 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1... |
| CVE-2026-30935 | MEDIUM | 4.4 | 0.1% | Mar 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1... |
| CVE-2026-28692 | MEDIUM | 4.8 | 0.3% | Mar 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1... |
| CVE-2026-28690 | MEDIUM | 6.5 | 0.1% | Mar 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1... |
| CVE-2026-28689 | MEDIUM | 6.3 | 0.1% | Mar 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1... |
| CVE-2026-28688 | MEDIUM | 5.3 | 0.2% | Mar 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1... |
| CVE-2026-28687 | MEDIUM | 5.3 | 0.2% | Mar 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1... |
| CVE-2026-28686 | MEDIUM | 6.8 | 0.1% | Mar 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1... |
| CVE-2026-28493 | MEDIUM | 6.5 | 0.2% | Mar 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1... |
| CVE-2026-28433 | MEDIUM | 4.3 | 0.2% | Mar 10, 2026 | Misskey is an open source, federated social media platform. All Misskey servers running versions 10.93.0 and later, but ... |
| CVE-2026-1776 | MEDIUM | 6.5 | 0.7% | Mar 10, 2026 | Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS ... |
| CVE-2026-3638 | MEDIUM | 5.9 | 0.2% | Mar 9, 2026 | Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a lo... |
| CVE-2026-3588 | MEDIUM | 5.5 | 0.1% | Mar 9, 2026 | A server-side request forgery (SSRF) vulnerability in IKEA Dirigera v2.866.4 allows an attacker to exfiltrate private ke... |
| CVE-2026-3089 | MEDIUM | 6.5 | 0.4% | Mar 9, 2026 | Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to ... |
| CVE-2026-2919 | MEDIUM | 4.3 | 0.2% | Mar 9, 2026 | Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _se... |
| CVE-2026-3819 | MEDIUM | 5.4 | 0.3% | Mar 9, 2026 | A vulnerability has been found in SourceCodester Resort Reservation System 1.0. The affected element is an unknown funct... |
| CVE-2026-21736 | MEDIUM | 4.4 | 0.1% | Mar 9, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to re... |
| CVE-2026-3817 | MEDIUM | 5.5 | 0.5% | Mar 9, 2026 | A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. This issue affects som... |
| CVE-2026-3816 | MEDIUM | 6.5 | 0.5% | Mar 9, 2026 | A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function inp... |
| CVE-2026-25604 | MEDIUM | 5.4 | 0.4% | Mar 9, 2026 | In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified agai... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now