2026 CVE Vulnerabilities

66,321 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-27885HIGH7.2Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability w...
CVE-2026-27834HIGH7.2Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability e...
CVE-2026-27833HIGH7.5Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API meth...
CVE-2026-27634CRITICAL9.8Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters...
CVE-2026-27481MEDIUM5.3Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be...
CVE-2026-27456MEDIUM4.7util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vuln...
CVE-2026-27447MEDIUM6.3OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 ...
CVE-2026-5485HIGH7.8OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux ...
CVE-2026-35562HIGH8.7Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow...
CVE-2026-35561CRITICAL9.8Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC drive...
CVE-2026-35560MEDIUM5.9Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0...
CVE-2026-35559HIGH7.1Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat ...
CVE-2026-35558HIGH7.8Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0...
CVE-2026-34511MEDIUM5.9OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it thr...
CVE-2026-32662MEDIUM6.9Development and test API endpoints are present that mirror production functionality.
CVE-2026-32646HIGH8.7A specific administrative endpoint is accessible without proper authentication, exposing device management functions.
CVE-2026-28767MEDIUM5.3A specific administrative endpoint notifications is accessible without proper authentication.
CVE-2026-28766HIGH7.5A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.
CVE-2026-26058MEDIUM6.1Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, ./manage.py import reads arb...
CVE-2026-25742MEDIUM5.3Zulip is an open-source team collaboration tool. Prior to version 11.6, Zulip is an open-source team collaboration tool....
CVE-2026-25197HIGH8.1A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API cal...
CVE-2026-22665HIGH8.6prompts.chat prior to commit 1464475, contains an identity confusion vulnerability due to inconsistent case-sensitive an...
CVE-2026-22664HIGH7.7prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in the Fal.ai media status pol...
CVE-2026-22663HIGH8.7prompts.chat prior to commit 7b81836 contains multiple authorization bypass vulnerabilities due to missing isPrivate che...
CVE-2026-22662MEDIUM5.3prompts.chat prior to commit 1464475 contains a blind server-side request forgery vulnerability in the Wiro media genera...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now