Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,782
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 901 - 920 of 36,778 CVEs

Relative Path Traversal vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Kvrocks
Published: Jun 25, 2026
Source: NVD

Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: 2.8.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Kvrocks
Published: Jun 25, 2026
Source: NVD
CVE-2026-56129 MEDIUM - 5.5

Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A logged-in user with no administrative privilege may access physical memory.

Vendor: Dynabook Inc., TOSHIBA CORPORATION
Product: Generic IO & Memory Access driver
Published: Jun 25, 2026
Source: NVD
CVE-2026-12937 HIGH - 7.5

The Tourfic โ€“ AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'post_id' parameter in all versions up to, and including, 2.22.7 due to insufficient escaping on the user supplied parameter and lack...

Vendor: themefic
Product: Tourfic โ€“ AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin
Published: Jun 25, 2026
Source: NVD
CVE-2026-9702 HIGH - 7.5

The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destination to be updated, allowing unauthenticated attackers to silently redirect the shipping destination of any pending or processi...

Published: Jun 25, 2026
Source: NVD
CVE-2026-5305 HIGH - 8.8

The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks

Published: Jun 25, 2026
Source: NVD
CVE-2026-12490 HIGH - 7.5

When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over TCP over the regular ...

Vendor: nlnetlabs
Product: nsd
Published: Jun 25, 2026
Source: NVD
CVE-2026-12246 HIGH - 8.1

NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.

Vendor: nlnetlabs
Product: nsd
Published: Jun 25, 2026
Source: NVD
CVE-2026-12245 HIGH - 7.5

NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response.

Vendor: nlnetlabs
Product: nsd
Published: Jun 25, 2026
Source: NVD
CVE-2026-12244 HIGH - 8.8

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size >...

Vendor: nlnetlabs
Product: nsd
Published: Jun 25, 2026
Source: NVD
CVE-2026-10824 MEDIUM - 6.5

The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently delete any user's course-progress records.

Vendor: Unknown
Product: Masteriyo LMS
Published: Jun 25, 2026
Source: NVD
CVE-2026-8330 MEDIUM - 4.4

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed sensitive information to be written to application logs due to insufficient filtering in a CI/CD API endpoint.

Vendor: gitlab
Product: gitlab
Published: Jun 25, 2026
Source: NVD
CVE-2026-5952 MEDIUM - 4.3

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to bypass package protection rules and overwrite protecte...

Vendor: gitlab
Product: gitlab
Published: Jun 25, 2026
Source: NVD
CVE-2026-5796 MEDIUM - 4.3

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with Reporter-level group permissions to view package metadata from projects with the Pack...

Vendor: gitlab
Product: gitlab
Published: Jun 25, 2026
Source: NVD
CVE-2026-5309 MEDIUM - 5.4

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to read or modify another group's virtual registry cleanup policy settings without autho...

Vendor: gitlab
Product: gitlab
Published: Jun 25, 2026
Source: NVD
CVE-2026-3176 LOW - 3.1

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with limited permissions to access project information due to insufficient authorization chec...

Vendor: gitlab
Product: gitlab
Published: Jun 25, 2026
Source: NVD
CVE-2026-2238 MEDIUM - 5.3

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to view confidential issue references on public projects due to improper authorization c...

Vendor: gitlab
Product: gitlab
Published: Jun 25, 2026
Source: NVD
CVE-2026-1606 MEDIUM - 4.3

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to conceal content within a Snippet due to improper input validation.

Vendor: gitlab
Product: gitlab
Published: Jun 25, 2026
Source: NVD
CVE-2026-13311 HIGH - 7.5

shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result parse() runs in O(n^2) time relative to the number of input tokens. An attacker who can supply an ...

Vendor: ljharb
Product: shell-quote
Published: Jun 25, 2026
Source: NVD

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to make requests to internal network resources through mir...

Vendor: GitLab
Product: GitLab
Published: Jun 25, 2026
Source: NVD