2026 CVE Vulnerabilities

48,169 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-12937HIGH7.5The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable ...
CVE-2026-9702HIGH7.5The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before...
CVE-2026-5305HIGH8.8The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not ...
CVE-2026-12490HIGH7.5When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate ...
CVE-2026-12246HIGH8.1NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the ad...
CVE-2026-12245HIGH7.5NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the serve...
CVE-2026-12244HIGH8.8If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS messa...
CVE-2026-13311HIGH8.7shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, whic...
CVE-2026-12053HIGH7.5GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions...
CVE-2026-12077HIGH7.5The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' para...
CVE-2026-8658HIGH8.8OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to ex...
CVE-2026-8664HIGH8.8OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to exe...
CVE-2026-9155HIGH8.8OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execut...
CVE-2026-57589HIGH7.8sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a c...
CVE-2026-9787HIGH8.8Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. This vulnerability allows rem...
CVE-2026-9786HIGH8.8Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote ...
CVE-2026-9785HIGH8.8Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remot...
CVE-2026-9784HIGH8.8Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remot...
CVE-2026-9783HIGH8.8Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability. This vulnerability allows re...
CVE-2026-9782HIGH8.8Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remot...
CVE-2026-9781HIGH8.8Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote ...
CVE-2026-9780HIGH8.8Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows rem...
CVE-2026-8663HIGH8.8OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execut...
CVE-2026-8659HIGH8.8OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to exe...
CVE-2026-7570HIGH8.8Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now