2026 CVE Vulnerabilities
53,206 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34770 | HIGH | 8.8 | 0.2% | Apr 4, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version... |
| CVE-2026-34769 | HIGH | 8.8 | 0.3% | Apr 4, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version... |
| CVE-2026-34768 | HIGH | 7.8 | 0.1% | Apr 4, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version... |
| CVE-2026-35468 | HIGH | 7.5 | 0.5% | Apr 3, 2026 | nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a... |
| CVE-2026-34954 | HIGH | 8.6 | 0.4% | Apr 3, 2026 | PraisonAI is a multi-agent teams system. Prior to version 1.5.95, FileTools.download_file() in praisonaiagents validates... |
| CVE-2026-34939 | HIGH | 7.5 | 0.4% | Apr 3, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.5.90, MCPToolIndex.search_tools() compiles a caller-supplied... |
| CVE-2026-34936 | HIGH | 7.7 | 0.3% | Apr 3, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.5.90, passthrough() and apassthrough() in praisonai accept a... |
| CVE-2026-34824 | HIGH | 7.5 | 0.7% | Apr 3, 2026 | Mesop is a Python-based UI framework that allows users to build web applications. From version 1.2.3 to before version 1... |
| CVE-2026-34607 | HIGH | 7.2 | 0.9% | Apr 3, 2026 | Emlog is an open source website building system. In versions 2.6.2 and prior, a path traversal vulnerability exists in t... |
| CVE-2026-33184 | HIGH | 7.5 | 0.5% | Apr 3, 2026 | nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a... |
| CVE-2026-34990 | HIGH | 7.8 | 0.3% | Apr 3, 2026 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 ... |
| CVE-2026-34980 | HIGH | 7.5 | 0.5% | Apr 3, 2026 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 ... |
| CVE-2026-33175 | HIGH | 8.8 | 0.4% | Apr 3, 2026 | OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to ver... |
| CVE-2026-28797 | HIGH | 8.8 | 0.4% | Apr 3, 2026 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Templ... |
| CVE-2026-27885 | HIGH | 7.2 | 0.4% | Apr 3, 2026 | Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability w... |
| CVE-2026-27834 | HIGH | 7.2 | 0.4% | Apr 3, 2026 | Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability e... |
| CVE-2026-27833 | HIGH | 7.5 | 1.6% | Apr 3, 2026 | Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API meth... |
| CVE-2026-5485 | HIGH | 7.8 | 0.7% | Apr 3, 2026 | OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux ... |
| CVE-2026-35562 | HIGH | 8.7 | 0.4% | Apr 3, 2026 | Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow... |
| CVE-2026-35559 | HIGH | 7.1 | 0.3% | Apr 3, 2026 | Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat ... |
| CVE-2026-35558 | HIGH | 7.8 | 0.3% | Apr 3, 2026 | Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0... |
| CVE-2026-32646 | HIGH | 8.7 | 0.5% | Apr 3, 2026 | A specific administrative endpoint is accessible without proper authentication, exposing device management functions. |
| CVE-2026-28766 | HIGH | 7.5 | 0.4% | Apr 3, 2026 | A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication. |
| CVE-2026-25197 | HIGH | 8.1 | 0.3% | Apr 3, 2026 | A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API cal... |
| CVE-2026-22665 | HIGH | 8.6 | 0.3% | Apr 3, 2026 | prompts.chat prior to commit 1464475, contains an identity confusion vulnerability due to inconsistent case-sensitive an... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now