2026 CVE Vulnerabilities
66,321 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27885 | HIGH | 7.2 | 0.4% | Apr 3, 2026 | Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability w... |
| CVE-2026-27834 | HIGH | 7.2 | 0.4% | Apr 3, 2026 | Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability e... |
| CVE-2026-27833 | HIGH | 7.5 | 1.6% | Apr 3, 2026 | Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API meth... |
| CVE-2026-27634 | CRITICAL | 9.8 | 0.7% | Apr 3, 2026 | Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters... |
| CVE-2026-27481 | MEDIUM | 5.3 | 0.2% | Apr 3, 2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be... |
| CVE-2026-27456 | MEDIUM | 4.7 | 0.1% | Apr 3, 2026 | util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vuln... |
| CVE-2026-27447 | MEDIUM | 6.3 | 0.3% | Apr 3, 2026 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 ... |
| CVE-2026-5485 | HIGH | 7.8 | 0.7% | Apr 3, 2026 | OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux ... |
| CVE-2026-35562 | HIGH | 8.7 | 0.4% | Apr 3, 2026 | Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow... |
| CVE-2026-35561 | CRITICAL | 9.8 | 0.5% | Apr 3, 2026 | Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC drive... |
| CVE-2026-35560 | MEDIUM | 5.9 | 0.3% | Apr 3, 2026 | Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0... |
| CVE-2026-35559 | HIGH | 7.1 | 0.3% | Apr 3, 2026 | Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat ... |
| CVE-2026-35558 | HIGH | 7.8 | 0.3% | Apr 3, 2026 | Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0... |
| CVE-2026-34511 | MEDIUM | 5.9 | 0.2% | Apr 3, 2026 | OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it thr... |
| CVE-2026-32662 | MEDIUM | 6.9 | 0.3% | Apr 3, 2026 | Development and test API endpoints are present that mirror production functionality. |
| CVE-2026-32646 | HIGH | 8.7 | 0.5% | Apr 3, 2026 | A specific administrative endpoint is accessible without proper authentication, exposing device management functions. |
| CVE-2026-28767 | MEDIUM | 5.3 | 0.4% | Apr 3, 2026 | A specific administrative endpoint notifications is accessible without proper authentication. |
| CVE-2026-28766 | HIGH | 7.5 | 0.4% | Apr 3, 2026 | A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication. |
| CVE-2026-26058 | MEDIUM | 6.1 | 0.2% | Apr 3, 2026 | Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, ./manage.py import reads arb... |
| CVE-2026-25742 | MEDIUM | 5.3 | 0.3% | Apr 3, 2026 | Zulip is an open-source team collaboration tool. Prior to version 11.6, Zulip is an open-source team collaboration tool.... |
| CVE-2026-25197 | HIGH | 8.1 | 0.3% | Apr 3, 2026 | A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API cal... |
| CVE-2026-22665 | HIGH | 8.6 | 0.3% | Apr 3, 2026 | prompts.chat prior to commit 1464475, contains an identity confusion vulnerability due to inconsistent case-sensitive an... |
| CVE-2026-22664 | HIGH | 7.7 | 0.3% | Apr 3, 2026 | prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in the Fal.ai media status pol... |
| CVE-2026-22663 | HIGH | 8.7 | 0.3% | Apr 3, 2026 | prompts.chat prior to commit 7b81836 contains multiple authorization bypass vulnerabilities due to missing isPrivate che... |
| CVE-2026-22662 | MEDIUM | 5.3 | 0.2% | Apr 3, 2026 | prompts.chat prior to commit 1464475 contains a blind server-side request forgery vulnerability in the Wiro media genera... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now