2026 CVE Vulnerabilities
44,992 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14371 | HIGH | 8.8 | — | Jul 16, 2026 | The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vul... |
| CVE-2026-13401 | HIGH | 7.5 | — | Jul 16, 2026 | XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_p... |
| CVE-2026-13397 | HIGH | 7.5 | 0.2% | Jul 16, 2026 | HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_... |
| CVE-2026-13104 | HIGH | 7.3 | — | Jul 16, 2026 | A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could al... |
| CVE-2026-13103 | HIGH | 7.3 | — | Jul 16, 2026 | A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market... |
| CVE-2026-59867 | HIGH | 7.1 | — | Jul 16, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota resolved OpenAPI $ref values by fetching re... |
| CVE-2026-57206 | HIGH | 8.6 | — | Jul 16, 2026 | SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions... |
| CVE-2026-53598 | HIGH | 7.5 | 1.1% | Jul 16, 2026 | Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...... |
| CVE-2026-53597 | HIGH | 8.7 | 0.9% | Jul 16, 2026 | Prompty is a markdown file format (.prompty) for LLM prompts. From 2.0.0-alpha.1 until 2.0.0-beta.3, the @prompty/core T... |
| CVE-2026-59863 | HIGH | 7 | — | Jul 16, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota honored a poisoned .kiota/workspace.json wo... |
| CVE-2026-59862 | HIGH | 7.5 | 1.0% | Jul 16, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Python generator let attacker-controlled ... |
| CVE-2026-59861 | HIGH | 7.5 | 1.5% | Jul 16, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Ruby generator embedded OpenAPI default f... |
| CVE-2026-59860 | HIGH | 8.7 | 1.0% | Jul 16, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.3, Kiota is affected by a code-generation injection ... |
| CVE-2026-59859 | HIGH | 8.7 | 1.0% | Jul 16, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.4, Kiota's PHP generator embedded OpenAPI descriptio... |
| CVE-2026-14254 | HIGH | 8.3 | — | Jul 16, 2026 | A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed... |
| CVE-2026-5674 | HIGH | 8.8 | 0.1% | Jul 16, 2026 | A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed application... |
| CVE-2026-56455 | HIGH | 7.5 | 0.2% | Jul 16, 2026 | HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The applicat... |
| CVE-2026-56454 | HIGH | 7.5 | 0.1% | Jul 16, 2026 | HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy ... |
| CVE-2026-35142 | HIGH | 8.2 | 0.2% | Jul 16, 2026 | HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP ad... |
| CVE-2026-35140 | HIGH | 7.2 | 0.2% | Jul 16, 2026 | HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The applicat... |
| CVE-2026-35149 | HIGH | 8.2 | 0.3% | Jul 16, 2026 | HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized us... |
| CVE-2026-35147 | HIGH | 8.2 | 0.3% | Jul 16, 2026 | HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verif... |
| CVE-2026-7543 | HIGH | 7.2 | 0.2% | Jul 16, 2026 | The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions ... |
| CVE-2026-6423 | HIGH | 8.5 | 0.1% | Jul 16, 2026 | A local privilege escalation vulnerability in ESET Inspect Connector. The vulnerability was caused by improper authenti... |
| CVE-2026-58078 | HIGH | 8.7 | 0.2% | Jul 16, 2026 | Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extensio... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now