2026 CVE Vulnerabilities

56,974 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56454HIGH7.5HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy ...
CVE-2026-56453CRITICAL9.8HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can inter...
CVE-2026-35145LOW3.1HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to ...
CVE-2026-35143MEDIUM6.5HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" ...
CVE-2026-35142HIGH8.2HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP ad...
CVE-2026-35141MEDIUM5.3HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to interce...
CVE-2026-35140HIGH7.2HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The applicat...
CVE-2026-9494MEDIUM5.5An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The cli...
CVE-2026-63306CRITICAL9.2stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed e...
CVE-2026-63305CRITICAL9.2AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and ...
CVE-2026-63304CRITICAL9.2AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the list...
CVE-2026-12391MEDIUM5An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) with...
CVE-2026-11386CRITICAL9An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools)....
CVE-2026-59249MEDIUM6.3Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malici...
CVE-2026-35149HIGH8.2HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized us...
CVE-2026-35148MEDIUM6.3HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints ar...
CVE-2026-35147HIGH8.2HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verif...
CVE-2026-35146MEDIUM6.3HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish conn...
CVE-2026-22752CRITICAL9.6Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affe...
CVE-2026-7543HIGH7.2The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions ...
CVE-2026-6424MEDIUM6.7Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the syste...
CVE-2026-6423HIGH8.5A local privilege escalation vulnerability in ESET Inspect Connector.  The vulnerability was caused by improper authenti...
CVE-2026-58078HIGH8.7Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extensio...
CVE-2026-15727MEDIUM4.9The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_roles' parameter in ...
CVE-2026-15651MEDIUM4.9The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' para...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now