2026 CVE Vulnerabilities

51,071 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56673HIGH7.5ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_path...
CVE-2026-56672HIGH8.2ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-control...
CVE-2026-56671HIGH7.5ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_previ...
CVE-2026-56670HIGH8.2ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpo...
CVE-2026-63220MEDIUM4.8CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-For...
CVE-2026-62323MEDIUM6.3Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the se...
CVE-2026-55502HIGH7.1Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin r...
CVE-2026-55499MEDIUM4.3Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscri...
CVE-2026-55497MEDIUM6.5Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image ...
CVE-2026-55496MEDIUM4.3Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActi...
CVE-2026-55495MEDIUM4.3Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-W...
CVE-2026-43833MEDIUM5.3Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-43832HIGH7.5Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-43831HIGH7.5Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-43830CRITICAL9.8Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-43829HIGH7.5Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-6890Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-6889Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-18157HIGH7.8A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit ...
CVE-2026-14541HIGH7.5An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mc...
CVE-2026-14540MEDIUM6.1A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-t...
CVE-2026-14539HIGH7.5An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up ...
CVE-2026-14538HIGH7.7An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Googl...
CVE-2026-14537CRITICAL9.8Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0...
CVE-2026-58039LOW3.3A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-wr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now