Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-56453 — HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerabili…

HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach th…

dfxanalytics | Remote | Authentication
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
3.1 LOW
CVE-2026-35145 — HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerabi…

HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses…

dfxanalytics | Remote | Misconfiguration
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
6.5 MEDIUM
CVE-2026-35143 — HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability.

HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies generated during authentication, which could allow…

dfxanalytics | Remote | Cross-Site Request Forgery
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
8.2 HIGH
CVE-2026-35142 — HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability.

HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote…

dfxanalytics | Remote | Information Disclosure
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
5.3 MEDIUM
CVE-2026-35141 — HCL DFXAnalytics is affected by a Login Replay Attack vulnerability

HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data to achieve unau…

dfxanalytics | Remote | Authentication
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
7.2 HIGH
CVE-2026-35140 — HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Coo…

HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during aut…

dfxanalytics | Remote | Cryptography
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
Showing 20 of 11406 Results