2026 CVE Vulnerabilities

45,093 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-5796MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and ...
CVE-2026-5309MEDIUM5.4GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19....
CVE-2026-2238MEDIUM5.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and ...
CVE-2026-1606MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and ...
CVE-2026-11379MEDIUM5.3GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, an...
CVE-2026-10712MEDIUM6.1GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and...
CVE-2026-10086MEDIUM5.4GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19....
CVE-2026-2508MEDIUM6.5The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in...
CVE-2026-12079MEDIUM6.5The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions...
CVE-2026-10833MEDIUM6.4The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stor...
CVE-2026-8662MEDIUM4.3Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows ...
CVE-2026-9154MEDIUM6.5Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write ...
CVE-2026-9153MEDIUM6.5Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read ar...
CVE-2026-39900MEDIUM6.1Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Reflecte...
CVE-2026-39899MEDIUM5.3Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Tra...
CVE-2026-9775MEDIUM6.5ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attack...
CVE-2026-9774MEDIUM6.5ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote at...
CVE-2026-54068MEDIUM5.9SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the /api/icon/getDynamicIcon endpoint is ...
CVE-2026-53766MEDIUM6.1Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From ...
CVE-2026-53765MEDIUM6.1Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From ...
CVE-2026-39897MEDIUM6.1Cacti is an open source performance and fault management framework. Versions 1.2.30 and below contain a Reflected XSS vu...
CVE-2026-10642MEDIUM4.6The Zephyr PL011 UART driver (drivers/serial/uart_pl011.c) contains an unbounded software loop in pl011_irq_tx_enable() ...
CVE-2026-52816MEDIUM5.4Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Jupyter Notebook (ipynb) sanitizer endpoint at POST...
CVE-2026-52815MEDIUM5.5Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs has an unauthenticated information disclosure vuln...
CVE-2026-52814MEDIUM5.5Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs built-in Go SSH server is vulnerable to an una...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now