2026 CVE Vulnerabilities
43,284 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13392 | HIGH | 7.2 | 0.2% | Jul 31, 2026 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a... |
| CVE-2026-12721 | HIGH | 8.6 | 0.2% | Jul 31, 2026 | The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before us... |
| CVE-2026-12720 | HIGH | 7.5 | 0.2% | Jul 31, 2026 | The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data ... |
| CVE-2026-12695 | HIGH | 8.1 | 0.2% | Jul 31, 2026 | The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted... |
| CVE-2026-12251 | HIGH | 8.1 | 0.1% | Jul 31, 2026 | The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it m... |
| CVE-2026-63222 | HIGH | 7.5 | 0.4% | Jul 31, 2026 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument us... |
| CVE-2026-56673 | HIGH | 7.5 | 0.4% | Jul 31, 2026 | ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_path... |
| CVE-2026-56672 | HIGH | 8.2 | — | Jul 31, 2026 | ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-control... |
| CVE-2026-56671 | HIGH | 7.5 | 0.7% | Jul 31, 2026 | ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_previ... |
| CVE-2026-56670 | HIGH | 8.2 | 0.2% | Jul 31, 2026 | ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpo... |
| CVE-2026-55502 | HIGH | 7.1 | — | Jul 31, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin r... |
| CVE-2026-43832 | HIGH | 7.5 | 0.1% | Jul 31, 2026 | Full details and mitigation steps are currently restricted and will be published at a later date. |
| CVE-2026-43831 | HIGH | 7.5 | 0.1% | Jul 31, 2026 | Full details and mitigation steps are currently restricted and will be published at a later date. |
| CVE-2026-43829 | HIGH | 7.5 | 0.1% | Jul 31, 2026 | Full details and mitigation steps are currently restricted and will be published at a later date. |
| CVE-2026-18157 | HIGH | 7.8 | 0.2% | Jul 31, 2026 | A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit ... |
| CVE-2026-14541 | HIGH | 7.5 | 0.3% | Jul 31, 2026 | An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mc... |
| CVE-2026-14539 | HIGH | 7.5 | 0.2% | Jul 31, 2026 | An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up ... |
| CVE-2026-14538 | HIGH | 7.7 | 0.2% | Jul 31, 2026 | An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Googl... |
| CVE-2026-66720 | HIGH | 7.1 | 0.2% | Jul 30, 2026 | The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherTy... |
| CVE-2026-66420 | HIGH | 8.8 | 0.2% | Jul 30, 2026 | MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated... |
| CVE-2026-66369 | HIGH | 7.1 | 0.2% | Jul 30, 2026 | The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-... |
| CVE-2026-66364 | HIGH | 7.1 | 0.2% | Jul 30, 2026 | The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 mu... |
| CVE-2026-66360 | HIGH | 8.7 | 0.3% | Jul 30, 2026 | The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A mis... |
| CVE-2026-65423 | HIGH | 8.8 | 0.6% | Jul 30, 2026 | An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to t... |
| CVE-2026-65421 | HIGH | 7.1 | 0.2% | Jul 30, 2026 | The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length v... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now