2026 CVE Vulnerabilities

64,704 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-101032HIGH7navi through 2.24.0 fails to properly escape cheatsheet variable values when substituting them into shell commands. Atta...
CVE-2026-100872HIGH7.5Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthentic...
CVE-2026-100871HIGH8.8Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT token...
CVE-2026-100870HIGH8.8Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the r...
CVE-2026-97164HIGH7Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extensio...
CVE-2026-93302HIGH8.3MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any ...
CVE-2026-89136HIGH8.3When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could accept an unsolicited s...
CVE-2026-89102HIGH8.3In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response s...
CVE-2026-100746HIGH7.3A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /web...
CVE-2026-100865HIGH8.8Heym before 0.0.53 contains multiple independent vulnerabilities. (1) The workflow condition evaluator uses Python eval(...
CVE-2026-100864HIGH8.8heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback re...
CVE-2026-100857HIGH8AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails t...
CVE-2026-100856HIGH8.8AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete mig...
CVE-2026-100852HIGH8.8AzuraCast through 0.23.x contains a command injection vulnerability in the Liquidsoap config generation for live recordi...
CVE-2026-100851HIGH7.6AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint...
CVE-2026-100850HIGH7.7AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote pl...
CVE-2026-100849HIGH7.1AzuraCast is a self-hosted web radio management suite. In AzuraCast before 0.23.8, the station webhook URL validation in...
CVE-2026-100848HIGH7.1AzuraCast (Composer package azuracast/azuracast) before 0.23.8 validates a station's "Remote Relay" URL only for URL syn...
CVE-2026-100847HIGH7.5AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListA...
CVE-2026-100846HIGH7.6MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/...
CVE-2026-100845HIGH7.8MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses n...
CVE-2026-100844HIGH8.4MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_run...
CVE-2026-100843HIGH7.8MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsa...
CVE-2026-100842HIGH7MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. Th...
CVE-2026-100841HIGH7.8In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weight...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now