2026 CVE Vulnerabilities

60,151 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41566CRITICAL9.4Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This issue affects Apache ...
CVE-2026-56129MEDIUM6.8Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insuf...
CVE-2026-12937HIGH7.5The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable ...
CVE-2026-9702HIGH7.5The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before...
CVE-2026-5305HIGH8.8The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not ...
CVE-2026-12490HIGH7.5When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate ...
CVE-2026-12246HIGH8.1NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the ad...
CVE-2026-12245HIGH7.5NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the serve...
CVE-2026-12244HIGH8.8If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS messa...
CVE-2026-10824MEDIUM6.5The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API con...
CVE-2026-8330MEDIUM4.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.11.6, 19.0 before 19.0.3, and 1...
CVE-2026-5952MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and...
CVE-2026-5796MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and ...
CVE-2026-5309MEDIUM5.4GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19....
CVE-2026-3176LOW3.1GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19....
CVE-2026-2238MEDIUM5.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and ...
CVE-2026-1606MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and ...
CVE-2026-13311HIGH8.7shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, whic...
CVE-2026-12635LOW3.1GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.11.6, 19.0 before 19.0.3, and 1...
CVE-2026-12053HIGH7.5GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions...
CVE-2026-11379MEDIUM5.3GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, an...
CVE-2026-10712MEDIUM6.1GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and...
CVE-2026-10086MEDIUM5.4GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19....
CVE-2026-0934LOW3.8GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19....
CVE-2026-2508MEDIUM6.5The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now