2026 CVE Vulnerabilities
51,071 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56673 | HIGH | 7.5 | 0.4% | Jul 31, 2026 | ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_path... |
| CVE-2026-56672 | HIGH | 8.2 | — | Jul 31, 2026 | ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-control... |
| CVE-2026-56671 | HIGH | 7.5 | 0.7% | Jul 31, 2026 | ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_previ... |
| CVE-2026-56670 | HIGH | 8.2 | 0.2% | Jul 31, 2026 | ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpo... |
| CVE-2026-63220 | MEDIUM | 4.8 | — | Jul 31, 2026 | CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-For... |
| CVE-2026-62323 | MEDIUM | 6.3 | 0.3% | Jul 31, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the se... |
| CVE-2026-55502 | HIGH | 7.1 | — | Jul 31, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin r... |
| CVE-2026-55499 | MEDIUM | 4.3 | 0.3% | Jul 31, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscri... |
| CVE-2026-55497 | MEDIUM | 6.5 | 0.5% | Jul 31, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image ... |
| CVE-2026-55496 | MEDIUM | 4.3 | — | Jul 31, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActi... |
| CVE-2026-55495 | MEDIUM | 4.3 | 0.4% | Jul 31, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-W... |
| CVE-2026-43833 | MEDIUM | 5.3 | 0.2% | Jul 31, 2026 | Full details and mitigation steps are currently restricted and will be published at a later date. |
| CVE-2026-43832 | HIGH | 7.5 | 0.2% | Jul 31, 2026 | Full details and mitigation steps are currently restricted and will be published at a later date. |
| CVE-2026-43831 | HIGH | 7.5 | 0.2% | Jul 31, 2026 | Full details and mitigation steps are currently restricted and will be published at a later date. |
| CVE-2026-43830 | CRITICAL | 9.8 | 0.3% | Jul 31, 2026 | Full details and mitigation steps are currently restricted and will be published at a later date. |
| CVE-2026-43829 | HIGH | 7.5 | 0.2% | Jul 31, 2026 | Full details and mitigation steps are currently restricted and will be published at a later date. |
| CVE-2026-6890 | — | — | — | Jul 31, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-6889 | — | — | — | Jul 31, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-18157 | HIGH | 7.8 | 0.2% | Jul 31, 2026 | A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit ... |
| CVE-2026-14541 | HIGH | 7.5 | 0.3% | Jul 31, 2026 | An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mc... |
| CVE-2026-14540 | MEDIUM | 6.1 | 0.2% | Jul 31, 2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-t... |
| CVE-2026-14539 | HIGH | 7.5 | 0.2% | Jul 31, 2026 | An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up ... |
| CVE-2026-14538 | HIGH | 7.7 | 0.2% | Jul 31, 2026 | An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Googl... |
| CVE-2026-14537 | CRITICAL | 9.8 | 0.2% | Jul 31, 2026 | Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0... |
| CVE-2026-58039 | LOW | 3.3 | 0.2% | Jul 31, 2026 | A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-wr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now