2026 CVE Vulnerabilities

48,149 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-53146HIGH7.1In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Limit XDomain response copy to actual ...
CVE-2026-53145HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/gem: Try to fix change_handle ioctl, attempt 4 ...
CVE-2026-53143HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix buffer overflow in SDMA queue check...
CVE-2026-53138HIGH7.1In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Bound VBIOS record-chain walk loop...
CVE-2026-53137HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp HDMI HDCP2 rx_id_list read t...
CVE-2026-53136HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp VBIOS HDMI retimer register ...
CVE-2026-53133HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/umem: Fix truncation for block sizes >= 4G Wh...
CVE-2026-53132HIGH7.1In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix potential unbounded skb queue vi...
CVE-2026-12937HIGH7.5The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable ...
CVE-2026-9702HIGH7.5The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before...
CVE-2026-5305HIGH8.8The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not ...
CVE-2026-12490HIGH7.5When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate ...
CVE-2026-12246HIGH8.1NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the ad...
CVE-2026-12245HIGH7.5NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the serve...
CVE-2026-12244HIGH8.8If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS messa...
CVE-2026-13311HIGH8.7shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, whic...
CVE-2026-12053HIGH7.5GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions...
CVE-2026-12077HIGH7.5The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' para...
CVE-2026-8658HIGH8.8OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to ex...
CVE-2026-8664HIGH8.8OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to exe...
CVE-2026-9155HIGH8.8OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execut...
CVE-2026-57589HIGH7.8sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a c...
CVE-2026-9787HIGH8.8Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. This vulnerability allows rem...
CVE-2026-9786HIGH8.8Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote ...
CVE-2026-9785HIGH8.8Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remot...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now