2026 CVE Vulnerabilities
45,093 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5796 | MEDIUM | 4.3 | 0.2% | Jun 25, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and ... |
| CVE-2026-5309 | MEDIUM | 5.4 | 0.2% | Jun 25, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.... |
| CVE-2026-2238 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and ... |
| CVE-2026-1606 | MEDIUM | 4.3 | 0.2% | Jun 25, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and ... |
| CVE-2026-11379 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, an... |
| CVE-2026-10712 | MEDIUM | 6.1 | 0.3% | Jun 25, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and... |
| CVE-2026-10086 | MEDIUM | 5.4 | 0.3% | Jun 25, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.... |
| CVE-2026-2508 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in... |
| CVE-2026-12079 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions... |
| CVE-2026-10833 | MEDIUM | 6.4 | 0.2% | Jun 25, 2026 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stor... |
| CVE-2026-8662 | MEDIUM | 4.3 | 0.2% | Jun 25, 2026 | Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows ... |
| CVE-2026-9154 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write ... |
| CVE-2026-9153 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read ar... |
| CVE-2026-39900 | MEDIUM | 6.1 | 0.2% | Jun 24, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Reflecte... |
| CVE-2026-39899 | MEDIUM | 5.3 | 0.3% | Jun 24, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Tra... |
| CVE-2026-9775 | MEDIUM | 6.5 | 1.2% | Jun 24, 2026 | ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attack... |
| CVE-2026-9774 | MEDIUM | 6.5 | 1.2% | Jun 24, 2026 | ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote at... |
| CVE-2026-54068 | MEDIUM | 5.9 | 0.2% | Jun 24, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the /api/icon/getDynamicIcon endpoint is ... |
| CVE-2026-53766 | MEDIUM | 6.1 | 0.1% | Jun 24, 2026 | Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From ... |
| CVE-2026-53765 | MEDIUM | 6.1 | 0.1% | Jun 24, 2026 | Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From ... |
| CVE-2026-39897 | MEDIUM | 6.1 | 0.2% | Jun 24, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and below contain a Reflected XSS vu... |
| CVE-2026-10642 | MEDIUM | 4.6 | 0.2% | Jun 24, 2026 | The Zephyr PL011 UART driver (drivers/serial/uart_pl011.c) contains an unbounded software loop in pl011_irq_tx_enable() ... |
| CVE-2026-52816 | MEDIUM | 5.4 | 0.7% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Jupyter Notebook (ipynb) sanitizer endpoint at POST... |
| CVE-2026-52815 | MEDIUM | 5.5 | 1.6% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs has an unauthenticated information disclosure vuln... |
| CVE-2026-52814 | MEDIUM | 5.5 | 0.5% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs built-in Go SSH server is vulnerable to an una... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now