2026 CVE Vulnerabilities
48,149 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53146 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Limit XDomain response copy to actual ... |
| CVE-2026-53145 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/gem: Try to fix change_handle ioctl, attempt 4 ... |
| CVE-2026-53143 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix buffer overflow in SDMA queue check... |
| CVE-2026-53138 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Bound VBIOS record-chain walk loop... |
| CVE-2026-53137 | HIGH | 7.8 | 0.2% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp HDMI HDCP2 rx_id_list read t... |
| CVE-2026-53136 | HIGH | 7.8 | 0.2% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp VBIOS HDMI retimer register ... |
| CVE-2026-53133 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/umem: Fix truncation for block sizes >= 4G Wh... |
| CVE-2026-53132 | HIGH | 7.1 | 0.1% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix potential unbounded skb queue vi... |
| CVE-2026-12937 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable ... |
| CVE-2026-9702 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before... |
| CVE-2026-5305 | HIGH | 8.8 | 0.3% | Jun 25, 2026 | The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not ... |
| CVE-2026-12490 | HIGH | 7.5 | 0.1% | Jun 25, 2026 | When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate ... |
| CVE-2026-12246 | HIGH | 8.1 | 0.3% | Jun 25, 2026 | NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the ad... |
| CVE-2026-12245 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the serve... |
| CVE-2026-12244 | HIGH | 8.8 | 0.3% | Jun 25, 2026 | If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS messa... |
| CVE-2026-13311 | HIGH | 8.7 | 0.4% | Jun 25, 2026 | shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, whic... |
| CVE-2026-12053 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions... |
| CVE-2026-12077 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' para... |
| CVE-2026-8658 | HIGH | 8.8 | 0.7% | Jun 25, 2026 | OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to ex... |
| CVE-2026-8664 | HIGH | 8.8 | 0.7% | Jun 25, 2026 | OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to exe... |
| CVE-2026-9155 | HIGH | 8.8 | 0.9% | Jun 25, 2026 | OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execut... |
| CVE-2026-57589 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a c... |
| CVE-2026-9787 | HIGH | 8.8 | 1.4% | Jun 25, 2026 | Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. This vulnerability allows rem... |
| CVE-2026-9786 | HIGH | 8.8 | 0.7% | Jun 25, 2026 | Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote ... |
| CVE-2026-9785 | HIGH | 8.8 | 0.7% | Jun 25, 2026 | Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remot... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now