2026 CVE Vulnerabilities

57,151 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56150HIGH7.5Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Exces...
CVE-2026-56149MEDIUM4.9Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce...
CVE-2026-56148MEDIUM6.5Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). ...
CVE-2026-54399HIGH7.5Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and ...
CVE-2026-49088MEDIUM4.4Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the option...
CVE-2026-49087MEDIUM6.5Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A...
CVE-2026-34117CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in text_to_subtitles.php (line 19) ...
CVE-2026-34116CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) without...
CVE-2026-34115CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe_amazon.php (line 15) ...
CVE-2026-34114CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate_text.php (line 18) wit...
CVE-2026-34113CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech_text.php (line 18) withou...
CVE-2026-34112CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac.php (line 18) without ...
CVE-2026-34111CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac_text.php (line 18) wit...
CVE-2026-34110CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) with...
CVE-2026-34109CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) without san...
CVE-2026-34108CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanit...
CVE-2026-34107CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without ...
CVE-2026-34106CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without ...
CVE-2026-34105HIGH8.8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line ...
CVE-2026-34104HIGH8.8Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124)...
CVE-2026-34103HIGH8.8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): ...
CVE-2026-34102HIGH8.8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16...
CVE-2026-34101HIGH8.8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): ...
CVE-2026-34100HIGH8.8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELE...
CVE-2026-34099CRITICAL9.8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): S...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now