VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
20,165 CVE recordsPage 567 of 1345 · EPSS data 2026.08.13
ReviewHigh
CVE-2026-5305

Email Address Encoder, email-encoder-premium

The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12490

NLnet Labs NSD, nsd

When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over TCP over the regular port, when the other conditions of the provide-xfr rule match.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12246

NLnet Labs NSD, nsd

NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12245

NLnet Labs NSD, nsd

NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12244

NLnet Labs NSD, nsd

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13311

ljharb shell-quote

shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result parse() runs in O(n^2) time relative to the number of input tokens. An attacker who can supply an attacker-controlled string to any code path that calls parse() (no shell metacharacters are required; plain space-separated words suffice) can block the single-threaded Node.js event loop for an extended period with a small input, resulting in a denial of service. There is no code execution or da...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12053

GitLab GitLab, gitlab

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to access sensitive information that had already been committed to a project, due to insufficient output filtering in Duo Workflows.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12077

wedevs Dokan Pro

The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' parameters in all versions up to, and including, 5.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-8666

Rapid7 InsightConnect Traceroute Plugin, insightconnect traceroute, linux kernel

OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host, port, max_ttl, count, or time_out request parameters due to insufficient input validation when constructing shell commands.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-8664

Rapid7 InsightConnect Finger Plugin, insightconnect finger

OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the user or host parameters due to insufficient input validation in shell command construction.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-8592

Rapid7 InsightConnect AWK Plugin, insightconnect awk, linux kernel

OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to unsafe shell command construction in the processing pipeline.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-9155

Rapid7 InsightConnect Sed Plugin, sed, linux kernel

OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter due to insufficient input validation.

The CVSS severity warrants an early asset and exposure review.