Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54367
Total
4306
Critical
16164
High
15850
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-100841 | HIGH | 7.8 | In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) … | Sep 27, 2026 |
| CVE-2026-100840 | HIGH | 7.8 | MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow … | Sep 27, 2026 |
| CVE-2026-100839 | HIGH | 8.4 | Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI … | Sep 27, 2026 |
| CVE-2026-100838 | HIGH | 8.1 | Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the … | Sep 27, 2026 |
| CVE-2026-100837 | LOW | 3.7 | Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration in the imagepuller. Config.registryFor strips a single trailing dot and then uses … | Sep 27, 2026 |
| CVE-2026-100836 | MEDIUM | 4.3 | Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSON function that fails to validate decoded ciphertext length before slicing. An authenticated workload … | Sep 27, 2026 |
| CVE-2026-100835 | HIGH | 7.4 | Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch … | Sep 27, 2026 |
| CVE-2026-100834 | MEDIUM | 5.9 | http4k's Digest authentication module (org.http4k:http4k-security-digest) before versions 6.48.0.0, 5.42.0.0 and 4.51.0.0 defaults the nonceVerifier parameter of ServerFilters.DigestAuth and DigestAuthProvider to { true }, so every … | Sep 27, 2026 |
| CVE-2026-100833 | HIGH | 8.2 | Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update … | Sep 27, 2026 |
| CVE-2026-100745 | MEDIUM | 6.3 | A vulnerability has been found in Edimax BR-6428nC 1.16. The impacted element is an unknown function of the file /goform/formWizSurvey of the component Wireless Wizard … | Sep 27, 2026 |
| CVE-2026-100744 | HIGH | 7.3 | A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the file app/Http/Middleware/CanUpdateResource.php of the component … | Sep 27, 2026 |
| CVE-2026-100725 | MEDIUM | 6.5 | http4k (Maven artifact org.http4k:http4k-core) before 6.48.0.0, 5.42.0.0, and 4.51.0.0 ships a BasicCookieStorage (client-side cookie store used by ClientFilters.Cookies) that does not enforce RFC 6265 scoping … | Sep 27, 2026 |
| CVE-2026-100724 | MEDIUM | 5.4 | http4k (Maven package org.http4k:http4k-core) before 6.49.0.0, 5.42.0.0 and 4.51.0.0 uses substring (Contains) matching on the Host header by default in reverseProxy() and reverseProxyRouting() when dispatching … | Sep 27, 2026 |
| CVE-2026-100723 | HIGH | 7.5 | vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength === length) to Buffers returned from host builtin modules. … | Sep 27, 2026 |
| CVE-2026-100722 | MEDIUM | 6.8 | vm2 before 3.12.2 does not apply host-side Promise rejection handling in the sandbox-to-host construct trap. In BaseHandler, the apply trap calls markHostPromiseHandled() on the returned … | Sep 27, 2026 |
| CVE-2026-100721 | CRITICAL | 9.0 | vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` … | Sep 27, 2026 |
| CVE-2025-71426 | HIGH | 7.1 | Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not verify the seed supplied by the recovering party. An … | Sep 27, 2026 |
| CVE-2025-71425 | HIGH | 7.3 | Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set … | Sep 27, 2026 |
| CVE-2025-71424 | LOW | 3.5 | Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and including 1.9.0. The VOLUME directive in a Dockerfile (config.volumes … | Sep 27, 2026 |
| CVE-2025-71423 | HIGH | 7.3 | Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workload … | Sep 27, 2026 |
| CVE-2025-71422 | MEDIUM | 5.7 | Contrast is a Kubernetes runtime for confidential containers. In versions before 1.12.1, the secure persistent volume feature is vulnerable to a malicious host supplying a … | Sep 27, 2026 |
| CVE-2026-100740 | CRITICAL | 9.9 | A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing … | Sep 27, 2026 |
| CVE-2026-100739 | HIGH | 7.3 | A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file viewresult.php. Performing a manipulation of the argument … | Sep 26, 2026 |
| CVE-2026-94408 | MEDIUM | 4.9 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | Sep 26, 2026 |
| CVE-2026-94400 | MEDIUM | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130) | Sep 26, 2026 |