Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54305
Total
4306
Critical
16147
High
15838
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-100854 | MEDIUM | 6.3 | AzuraCast before 0.23.6 lacks RequireInternalConnection middleware on the Liquidsoap API endpoint and incorrectly derives the AutoDJ flag from header presence rather than validated value. Users … | Sep 27, 2026 |
| CVE-2026-100853 | MEDIUM | 5.9 | In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allowing unauthenticated users to download media files excluded from On-Demand-enabled … | Sep 27, 2026 |
| CVE-2026-100852 | HIGH | 8.8 | AzuraCast before 0.23.8 contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run … | Sep 27, 2026 |
| CVE-2026-100851 | HIGH | 7.6 | AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to … | Sep 27, 2026 |
| CVE-2026-100850 | HIGH | 7.7 | AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote playlist fetch (backend/src/Radio/AutoDJ/QueueBuilder.php, getMediaFromRemoteUrl()). A user with the … | Sep 27, 2026 |
| CVE-2026-100849 | HIGH | 7.1 | AzuraCast is a self-hosted web radio management suite. In AzuraCast before 0.23.8, the station webhook URL validation in AbstractConnector::getValidUrl() (backend/src/Webhook/Connector/AbstractConnector.php), used by the Generic and … | Sep 27, 2026 |
| CVE-2026-100848 | HIGH | 7.1 | AzuraCast (Composer package azuracast/azuracast) before 0.23.8 validates a station's "Remote Relay" URL only for URL syntax and an http/https scheme (Utilities\Urls::parseUserUrl, used by StationRemote::getUrlAsUri) and … | Sep 27, 2026 |
| CVE-2026-100847 | HIGH | 7.5 | AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter … | Sep 27, 2026 |
| CVE-2026-100846 | HIGH | 7.6 | MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its … | Sep 27, 2026 |
| CVE-2026-100845 | HIGH | 7.8 | MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with allow_pickle=True when loading .npy and .npz files. Attackers … | Sep 27, 2026 |
| CVE-2026-100844 | HIGH | 8.4 | MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner). User-controlled values taken from the YAML configuration file (notably dataset_name_or_id) and … | Sep 27, 2026 |
| CVE-2026-100843 | HIGH | 7.8 | MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserialization in monai/auto3dseg/utils.py. Attackers can craft malicious … | Sep 27, 2026 |
| CVE-2026-100842 | HIGH | 7.0 | MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. The function validates shape expressions with a helper that walks the AST and … | Sep 27, 2026 |
| CVE-2026-100841 | HIGH | 7.8 | In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) … | Sep 27, 2026 |
| CVE-2026-100840 | HIGH | 7.8 | MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow … | Sep 27, 2026 |
| CVE-2026-100839 | HIGH | 8.4 | Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI … | Sep 27, 2026 |
| CVE-2026-100838 | HIGH | 8.1 | Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the … | Sep 27, 2026 |
| CVE-2026-100837 | LOW | 3.7 | Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration in the imagepuller. Config.registryFor strips a single trailing dot and then uses … | Sep 27, 2026 |
| CVE-2026-100836 | MEDIUM | 4.3 | Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSON function that fails to validate decoded ciphertext length before slicing. An authenticated workload … | Sep 27, 2026 |
| CVE-2026-100835 | HIGH | 7.4 | Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch … | Sep 27, 2026 |
| CVE-2026-100834 | MEDIUM | 5.9 | http4k's Digest authentication module (org.http4k:http4k-security-digest) before versions 6.48.0.0, 5.42.0.0 and 4.51.0.0 defaults the nonceVerifier parameter of ServerFilters.DigestAuth and DigestAuthProvider to { true }, so every … | Sep 27, 2026 |
| CVE-2026-100833 | HIGH | 8.2 | Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update … | Sep 27, 2026 |
| CVE-2026-100745 | MEDIUM | 6.3 | A vulnerability has been found in Edimax BR-6428nC 1.16. The impacted element is an unknown function of the file /goform/formWizSurvey of the component Wireless Wizard … | Sep 27, 2026 |
| CVE-2026-100744 | HIGH | 7.3 | A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the file app/Http/Middleware/CanUpdateResource.php of the component … | Sep 27, 2026 |
| CVE-2026-100725 | MEDIUM | 6.5 | http4k (Maven artifact org.http4k:http4k-core) before 6.48.0.0, 5.42.0.0, and 4.51.0.0 ships a BasicCookieStorage (client-side cookie store used by ClientFilters.Cookies) that does not enforce RFC 6265 scoping … | Sep 27, 2026 |