2026 CVE Vulnerabilities
56,974 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56454 | HIGH | 7.5 | 0.1% | Jul 16, 2026 | HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy ... |
| CVE-2026-56453 | CRITICAL | 9.8 | 0.2% | Jul 16, 2026 | HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can inter... |
| CVE-2026-35145 | LOW | 3.1 | 0.2% | Jul 16, 2026 | HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to ... |
| CVE-2026-35143 | MEDIUM | 6.5 | 0.2% | Jul 16, 2026 | HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" ... |
| CVE-2026-35142 | HIGH | 8.2 | 0.2% | Jul 16, 2026 | HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP ad... |
| CVE-2026-35141 | MEDIUM | 5.3 | 0.2% | Jul 16, 2026 | HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to interce... |
| CVE-2026-35140 | HIGH | 7.2 | 0.2% | Jul 16, 2026 | HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The applicat... |
| CVE-2026-9494 | MEDIUM | 5.5 | — | Jul 16, 2026 | An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The cli... |
| CVE-2026-63306 | CRITICAL | 9.2 | — | Jul 16, 2026 | stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed e... |
| CVE-2026-63305 | CRITICAL | 9.2 | 1.4% | Jul 16, 2026 | AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and ... |
| CVE-2026-63304 | CRITICAL | 9.2 | 1.4% | Jul 16, 2026 | AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the list... |
| CVE-2026-12391 | MEDIUM | 5 | — | Jul 16, 2026 | An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) with... |
| CVE-2026-11386 | CRITICAL | 9 | — | Jul 16, 2026 | An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools).... |
| CVE-2026-59249 | MEDIUM | 6.3 | — | Jul 16, 2026 | Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malici... |
| CVE-2026-35149 | HIGH | 8.2 | 0.3% | Jul 16, 2026 | HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized us... |
| CVE-2026-35148 | MEDIUM | 6.3 | 0.2% | Jul 16, 2026 | HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints ar... |
| CVE-2026-35147 | HIGH | 8.2 | 0.3% | Jul 16, 2026 | HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verif... |
| CVE-2026-35146 | MEDIUM | 6.3 | 0.1% | Jul 16, 2026 | HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish conn... |
| CVE-2026-22752 | CRITICAL | 9.6 | 0.5% | Jul 16, 2026 | Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affe... |
| CVE-2026-7543 | HIGH | 7.2 | 0.2% | Jul 16, 2026 | The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions ... |
| CVE-2026-6424 | MEDIUM | 6.7 | 0.1% | Jul 16, 2026 | Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the syste... |
| CVE-2026-6423 | HIGH | 8.5 | 0.1% | Jul 16, 2026 | A local privilege escalation vulnerability in ESET Inspect Connector. The vulnerability was caused by improper authenti... |
| CVE-2026-58078 | HIGH | 8.7 | 0.2% | Jul 16, 2026 | Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extensio... |
| CVE-2026-15727 | MEDIUM | 4.9 | — | Jul 16, 2026 | The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_roles' parameter in ... |
| CVE-2026-15651 | MEDIUM | 4.9 | 0.3% | Jul 16, 2026 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' para... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now