2026 CVE Vulnerabilities
64,704 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-101032 | HIGH | 7 | — | Sep 27, 2026 | navi through 2.24.0 fails to properly escape cheatsheet variable values when substituting them into shell commands. Atta... |
| CVE-2026-100872 | HIGH | 7.5 | — | Sep 27, 2026 | Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthentic... |
| CVE-2026-100871 | HIGH | 8.8 | — | Sep 27, 2026 | Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT token... |
| CVE-2026-100870 | HIGH | 8.8 | — | Sep 27, 2026 | Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the r... |
| CVE-2026-97164 | HIGH | 7 | — | Sep 27, 2026 | Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extensio... |
| CVE-2026-93302 | HIGH | 8.3 | — | Sep 27, 2026 | MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any ... |
| CVE-2026-89136 | HIGH | 8.3 | — | Sep 27, 2026 | When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could accept an unsolicited s... |
| CVE-2026-89102 | HIGH | 8.3 | — | Sep 27, 2026 | In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response s... |
| CVE-2026-100746 | HIGH | 7.3 | — | Sep 27, 2026 | A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /web... |
| CVE-2026-100865 | HIGH | 8.8 | — | Sep 27, 2026 | Heym before 0.0.53 contains multiple independent vulnerabilities. (1) The workflow condition evaluator uses Python eval(... |
| CVE-2026-100864 | HIGH | 8.8 | — | Sep 27, 2026 | heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback re... |
| CVE-2026-100857 | HIGH | 8 | — | Sep 27, 2026 | AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails t... |
| CVE-2026-100856 | HIGH | 8.8 | — | Sep 27, 2026 | AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete mig... |
| CVE-2026-100852 | HIGH | 8.8 | — | Sep 27, 2026 | AzuraCast through 0.23.x contains a command injection vulnerability in the Liquidsoap config generation for live recordi... |
| CVE-2026-100851 | HIGH | 7.6 | — | Sep 27, 2026 | AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint... |
| CVE-2026-100850 | HIGH | 7.7 | — | Sep 27, 2026 | AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote pl... |
| CVE-2026-100849 | HIGH | 7.1 | — | Sep 27, 2026 | AzuraCast is a self-hosted web radio management suite. In AzuraCast before 0.23.8, the station webhook URL validation in... |
| CVE-2026-100848 | HIGH | 7.1 | — | Sep 27, 2026 | AzuraCast (Composer package azuracast/azuracast) before 0.23.8 validates a station's "Remote Relay" URL only for URL syn... |
| CVE-2026-100847 | HIGH | 7.5 | — | Sep 27, 2026 | AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListA... |
| CVE-2026-100846 | HIGH | 7.6 | — | Sep 27, 2026 | MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/... |
| CVE-2026-100845 | HIGH | 7.8 | — | Sep 27, 2026 | MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses n... |
| CVE-2026-100844 | HIGH | 8.4 | — | Sep 27, 2026 | MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_run... |
| CVE-2026-100843 | HIGH | 7.8 | — | Sep 27, 2026 | MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsa... |
| CVE-2026-100842 | HIGH | 7 | — | Sep 27, 2026 | MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. Th... |
| CVE-2026-100841 | HIGH | 7.8 | — | Sep 27, 2026 | In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weight... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now