CVE Find is a real-time vulnerability database indexing 398 473 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 2870 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-100741 |
2026-09-27 07h12 +00:00 |
Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versio... |
9.8 |
Critical |
|
CVE-2026-100864 |
2026-09-27 02h17 +00:00 |
heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/fi... Code Injection |
8.8 |
High |
|
CVE-2026-100856 |
2026-09-27 02h17 +00:00 |
AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field d... Code Injection |
8.8 |
High |
|
CVE-2026-100852 |
2026-09-27 02h17 +00:00 |
AzuraCast through 0.23.x contains a command injection vulnerability in the Liquidsoap config generat... OS Command Injection |
8.8 |
High |
|
CVE-2026-100844 |
2026-09-27 02h17 +00:00 |
MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps... OS Command Injection |
8.4 |
High |
|
CVE-2026-100839 |
2026-09-27 02h17 +00:00 |
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest ke... Code Injection |
8.4 |
High |
|
CVE-2026-100833 |
2026-09-27 02h17 +00:00 |
Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to... |
8.2 |
High |
|
CVE-2026-100721 |
2026-09-27 02h17 +00:00 |
vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an e... Authorization problems |
9 |
Critical |
|
CVE-2026-100865 |
2026-09-27 01h28 +00:00 |
Heym before 0.0.53 contains multiple independent vulnerabilities. (1) The workflow condition evaluat... Code Injection |
8.7 |
High |
|
CVE-2026-100740 |
2026-09-27 01h17 +00:00 |
A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_param... Overflow |
9.9 |
Critical |