2026 CVE Vulnerabilities
57,151 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56150 | HIGH | 7.5 | 0.3% | Jul 1, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Exces... |
| CVE-2026-56149 | MEDIUM | 4.9 | 0.3% | Jul 1, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce... |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.3% | Jul 1, 2026 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). ... |
| CVE-2026-54399 | HIGH | 7.5 | 0.6% | Jul 1, 2026 | Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and ... |
| CVE-2026-49088 | MEDIUM | 4.4 | 0.2% | Jul 1, 2026 | Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the option... |
| CVE-2026-49087 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A... |
| CVE-2026-34117 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in text_to_subtitles.php (line 19) ... |
| CVE-2026-34116 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) without... |
| CVE-2026-34115 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe_amazon.php (line 15) ... |
| CVE-2026-34114 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate_text.php (line 18) wit... |
| CVE-2026-34113 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech_text.php (line 18) withou... |
| CVE-2026-34112 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac.php (line 18) without ... |
| CVE-2026-34111 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac_text.php (line 18) wit... |
| CVE-2026-34110 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) with... |
| CVE-2026-34109 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) without san... |
| CVE-2026-34108 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanit... |
| CVE-2026-34107 | CRITICAL | 9.8 | 0.7% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without ... |
| CVE-2026-34106 | CRITICAL | 9.8 | 0.7% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without ... |
| CVE-2026-34105 | HIGH | 8.8 | 0.4% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line ... |
| CVE-2026-34104 | HIGH | 8.8 | 0.4% | Jul 1, 2026 | Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124)... |
| CVE-2026-34103 | HIGH | 8.8 | 0.4% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): ... |
| CVE-2026-34102 | HIGH | 8.8 | 0.4% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16... |
| CVE-2026-34101 | HIGH | 8.8 | 0.4% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): ... |
| CVE-2026-34100 | HIGH | 8.8 | 0.4% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELE... |
| CVE-2026-34099 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): S... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now