2026 CVE Vulnerabilities

44,992 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-14371HIGH8.8The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vul...
CVE-2026-13401HIGH7.5XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_p...
CVE-2026-13397HIGH7.5HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_...
CVE-2026-13104HIGH7.3A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could al...
CVE-2026-13103HIGH7.3A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market...
CVE-2026-59867HIGH7.1Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota resolved OpenAPI $ref values by fetching re...
CVE-2026-57206HIGH8.6SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions...
CVE-2026-53598HIGH7.5Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:......
CVE-2026-53597HIGH8.7Prompty is a markdown file format (.prompty) for LLM prompts. From 2.0.0-alpha.1 until 2.0.0-beta.3, the @prompty/core T...
CVE-2026-59863HIGH7Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota honored a poisoned .kiota/workspace.json wo...
CVE-2026-59862HIGH7.5Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Python generator let attacker-controlled ...
CVE-2026-59861HIGH7.5Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Ruby generator embedded OpenAPI default f...
CVE-2026-59860HIGH8.7Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.3, Kiota is affected by a code-generation injection ...
CVE-2026-59859HIGH8.7Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.4, Kiota's PHP generator embedded OpenAPI descriptio...
CVE-2026-14254HIGH8.3A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed...
CVE-2026-5674HIGH8.8A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed application...
CVE-2026-56455HIGH7.5HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The applicat...
CVE-2026-56454HIGH7.5HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy ...
CVE-2026-35142HIGH8.2HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP ad...
CVE-2026-35140HIGH7.2HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The applicat...
CVE-2026-35149HIGH8.2HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized us...
CVE-2026-35147HIGH8.2HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verif...
CVE-2026-7543HIGH7.2The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions ...
CVE-2026-6423HIGH8.5A local privilege escalation vulnerability in ESET Inspect Connector.  The vulnerability was caused by improper authenti...
CVE-2026-58078HIGH8.7Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extensio...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now