Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54305
Total
4306
Critical
16147
High
15838
Medium
CVE ID Severity Score Description Published
CVE-2026-100854 MEDIUM 6.3 AzuraCast before 0.23.6 lacks RequireInternalConnection middleware on the Liquidsoap API endpoint and incorrectly derives the AutoDJ flag from header presence rather than validated value. Users … Sep 27, 2026
CVE-2026-100853 MEDIUM 5.9 In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allowing unauthenticated users to download media files excluded from On-Demand-enabled … Sep 27, 2026
CVE-2026-100852 HIGH 8.8 AzuraCast before 0.23.8 contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run … Sep 27, 2026
CVE-2026-100851 HIGH 7.6 AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to … Sep 27, 2026
CVE-2026-100850 HIGH 7.7 AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote playlist fetch (backend/src/Radio/AutoDJ/QueueBuilder.php, getMediaFromRemoteUrl()). A user with the … Sep 27, 2026
CVE-2026-100849 HIGH 7.1 AzuraCast is a self-hosted web radio management suite. In AzuraCast before 0.23.8, the station webhook URL validation in AbstractConnector::getValidUrl() (backend/src/Webhook/Connector/AbstractConnector.php), used by the Generic and … Sep 27, 2026
CVE-2026-100848 HIGH 7.1 AzuraCast (Composer package azuracast/azuracast) before 0.23.8 validates a station's "Remote Relay" URL only for URL syntax and an http/https scheme (Utilities\Urls::parseUserUrl, used by StationRemote::getUrlAsUri) and … Sep 27, 2026
CVE-2026-100847 HIGH 7.5 AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter … Sep 27, 2026
CVE-2026-100846 HIGH 7.6 MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its … Sep 27, 2026
CVE-2026-100845 HIGH 7.8 MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with allow_pickle=True when loading .npy and .npz files. Attackers … Sep 27, 2026
CVE-2026-100844 HIGH 8.4 MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner). User-controlled values taken from the YAML configuration file (notably dataset_name_or_id) and … Sep 27, 2026
CVE-2026-100843 HIGH 7.8 MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserialization in monai/auto3dseg/utils.py. Attackers can craft malicious … Sep 27, 2026
CVE-2026-100842 HIGH 7.0 MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. The function validates shape expressions with a helper that walks the AST and … Sep 27, 2026
CVE-2026-100841 HIGH 7.8 In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) … Sep 27, 2026
CVE-2026-100840 HIGH 7.8 MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow … Sep 27, 2026
CVE-2026-100839 HIGH 8.4 Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI … Sep 27, 2026
CVE-2026-100838 HIGH 8.1 Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the … Sep 27, 2026
CVE-2026-100837 LOW 3.7 Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration in the imagepuller. Config.registryFor strips a single trailing dot and then uses … Sep 27, 2026
CVE-2026-100836 MEDIUM 4.3 Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSON function that fails to validate decoded ciphertext length before slicing. An authenticated workload … Sep 27, 2026
CVE-2026-100835 HIGH 7.4 Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch … Sep 27, 2026
CVE-2026-100834 MEDIUM 5.9 http4k's Digest authentication module (org.http4k:http4k-security-digest) before versions 6.48.0.0, 5.42.0.0 and 4.51.0.0 defaults the nonceVerifier parameter of ServerFilters.DigestAuth and DigestAuthProvider to { true }, so every … Sep 27, 2026
CVE-2026-100833 HIGH 8.2 Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update … Sep 27, 2026
CVE-2026-100745 MEDIUM 6.3 A vulnerability has been found in Edimax BR-6428nC 1.16. The impacted element is an unknown function of the file /goform/formWizSurvey of the component Wireless Wizard … Sep 27, 2026
CVE-2026-100744 HIGH 7.3 A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the file app/Http/Middleware/CanUpdateResource.php of the component … Sep 27, 2026
CVE-2026-100725 MEDIUM 6.5 http4k (Maven artifact org.http4k:http4k-core) before 6.48.0.0, 5.42.0.0, and 4.51.0.0 ships a BasicCookieStorage (client-side cookie store used by ClientFilters.Cookies) that does not enforce RFC 6265 scoping … Sep 27, 2026