2026 CVE Vulnerabilities

65,368 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-100850HIGH7.7AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote pl...
CVE-2026-100849HIGH7.1AzuraCast is a self-hosted web radio management suite. In AzuraCast before 0.23.8, the station webhook URL validation in...
CVE-2026-100848HIGH7.1AzuraCast (Composer package azuracast/azuracast) before 0.23.8 validates a station's "Remote Relay" URL only for URL syn...
CVE-2026-100847HIGH7.5AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListA...
CVE-2026-100846HIGH7.6MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/...
CVE-2026-100845HIGH7.8MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses n...
CVE-2026-100844HIGH8.4MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_run...
CVE-2026-100843HIGH7.8MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsa...
CVE-2026-100842HIGH7MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. Th...
CVE-2026-100841HIGH7.8In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weight...
CVE-2026-100840HIGH7.8MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _tar...
CVE-2026-100839HIGH8.4Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML hand...
CVE-2026-100838HIGH8.1Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generate...
CVE-2026-100837LOW3.7Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration...
CVE-2026-100836MEDIUM4.3Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSO...
CVE-2026-100835HIGH7.4Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report ...
CVE-2026-100834MEDIUM5.9http4k's Digest authentication module (org.http4k:http4k-security-digest) before versions 6.48.0.0, 5.42.0.0 and 4.51.0....
CVE-2026-100833HIGH8.2Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all containe...
CVE-2026-100745MEDIUM6.3A vulnerability has been found in Edimax BR-6428nC 1.16. The impacted element is an unknown function of the file /goform...
CVE-2026-100744HIGH7.3A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the file app/Htt...
CVE-2026-100725MEDIUM6.5http4k (Maven artifact org.http4k:http4k-core) before 6.48.0.0, 5.42.0.0, and 4.51.0.0 ships a BasicCookieStorage (clien...
CVE-2026-100724MEDIUM5.4http4k (Maven package org.http4k:http4k-core) before 6.49.0.0, 5.42.0.0 and 4.51.0.0 uses substring (Contains) matching ...
CVE-2026-100723HIGH7.5vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength ==...
CVE-2026-100722MEDIUM6.8vm2 before 3.12.2 does not apply host-side Promise rejection handling in the sandbox-to-host construct trap. In BaseHand...
CVE-2026-100721CRITICAL9vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now