2026 CVE Vulnerabilities

52,659 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-1919MEDIUM5.3The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthoriz...
CVE-2026-1508MEDIUM4.3The Court Reservation WordPress plugin before 1.10.9 does not have CSRF check in place when deleting events, which coul...
CVE-2026-0489MEDIUM6.1Due to insufficient validation of user-controlled input in the URLs query parameter. SAP Business One Job Service could ...
CVE-2026-31802MEDIUM5.5node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink t...
CVE-2026-30937MEDIUM6.1ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-30936MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-30935MEDIUM4.4ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28692MEDIUM4.8ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28690MEDIUM6.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28689MEDIUM6.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28688MEDIUM5.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28687MEDIUM5.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28686MEDIUM6.8ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28493MEDIUM6.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28433MEDIUM4.3Misskey is an open source, federated social media platform. All Misskey servers running versions 10.93.0 and later, but ...
CVE-2026-1776MEDIUM6.5Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS ...
CVE-2026-3638MEDIUM5.9Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a lo...
CVE-2026-3588MEDIUM5.5A server-side request forgery (SSRF) vulnerability in IKEA Dirigera v2.866.4 allows an attacker to exfiltrate private ke...
CVE-2026-3089MEDIUM6.5Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to ...
CVE-2026-2919MEDIUM4.3Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _se...
CVE-2026-3819MEDIUM5.4A vulnerability has been found in SourceCodester Resort Reservation System 1.0. The affected element is an unknown funct...
CVE-2026-21736MEDIUM4.4Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to re...
CVE-2026-3817MEDIUM5.5A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. This issue affects som...
CVE-2026-3816MEDIUM6.5A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function inp...
CVE-2026-25604MEDIUM5.4In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified agai...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now