2026 CVE Vulnerabilities

43,284 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-13392HIGH7.2The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a...
CVE-2026-12721HIGH8.6The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before us...
CVE-2026-12720HIGH7.5The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data ...
CVE-2026-12695HIGH8.1The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted...
CVE-2026-12251HIGH8.1The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it m...
CVE-2026-63222HIGH7.5CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument us...
CVE-2026-56673HIGH7.5ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_path...
CVE-2026-56672HIGH8.2ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-control...
CVE-2026-56671HIGH7.5ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_previ...
CVE-2026-56670HIGH8.2ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpo...
CVE-2026-55502HIGH7.1Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin r...
CVE-2026-43832HIGH7.5Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-43831HIGH7.5Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-43829HIGH7.5Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-18157HIGH7.8A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit ...
CVE-2026-14541HIGH7.5An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mc...
CVE-2026-14539HIGH7.5An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up ...
CVE-2026-14538HIGH7.7An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Googl...
CVE-2026-66720HIGH7.1The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherTy...
CVE-2026-66420HIGH8.8MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated...
CVE-2026-66369HIGH7.1The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-...
CVE-2026-66364HIGH7.1The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 mu...
CVE-2026-66360HIGH8.7The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A mis...
CVE-2026-65423HIGH8.8An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to t...
CVE-2026-65421HIGH7.1The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length v...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now