Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54367
Total
4306
Critical
16164
High
15850
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-100746 | HIGH | 7.3 | A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /webhooks/source/github/redirect of the component GitHub App Setup … | Sep 27, 2026 |
| CVE-2026-100865 | HIGH | 8.8 | Heym before 0.0.53 evaluates workflow condition expressions using Python's eval() with insufficient sandboxing in the workflow executor service. Authenticated users can edit workflow condition nodes … | Sep 27, 2026 |
| CVE-2026-100864 | HIGH | 8.8 | heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback resolver that allows authenticated users to execute arbitrary Python … | Sep 27, 2026 |
| CVE-2026-100863 | MEDIUM | 5.0 | Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both remediated in app/services/ssrf_guard.py in 0.0.91. First, the LLM image-edit input loader … | Sep 27, 2026 |
| CVE-2026-100862 | MEDIUM | 4.9 | heym, a workflow automation platform, stores and returns multiple capability secrets in plaintext in versions prior to 0.0.91. Affected secrets include webhook header-auth values (returned … | Sep 27, 2026 |
| CVE-2026-100861 | MEDIUM | 5.0 | heym before 0.0.105 fails to apply egress guards to integration services that use credential-supplied base URLs, allowing authenticated users to bypass SSRF protections. Attackers can … | Sep 27, 2026 |
| CVE-2026-100860 | MEDIUM | 5.5 | heym before 0.0.105 does not act on the result of the credential authorization lookup in the Redis workflow node (backend/app/services/node_execution/nodes/redis_node.py). When _get_accessible_credential returns None — … | Sep 27, 2026 |
| CVE-2026-100859 | MEDIUM | 6.5 | Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that allows collaborators with shared credential access to exfiltrate the credential owner's … | Sep 27, 2026 |
| CVE-2026-100858 | MEDIUM | 6.8 | heym before 0.0.109 contains a server-side request forgery vulnerability in the Slack, Discord, and Crawler workflow nodes. These nodes issue HTTP requests to URLs taken … | Sep 27, 2026 |
| CVE-2026-100857 | HIGH | 8.0 | AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media … | Sep 27, 2026 |
| CVE-2026-100856 | HIGH | 8.8 | AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete migration from the vulnerable cleanUpString method to toRawString. … | Sep 27, 2026 |
| CVE-2026-100855 | MEDIUM | 6.5 | AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station/{station_id}/file/{id}/play endpoint that allows authenticated users to download media files from any station. … | Sep 27, 2026 |
| CVE-2026-100854 | MEDIUM | 6.3 | AzuraCast before 0.23.6 lacks RequireInternalConnection middleware on the Liquidsoap API endpoint and incorrectly derives the AutoDJ flag from header presence rather than validated value. Users … | Sep 27, 2026 |
| CVE-2026-100853 | MEDIUM | 5.9 | In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allowing unauthenticated users to download media files excluded from On-Demand-enabled … | Sep 27, 2026 |
| CVE-2026-100852 | HIGH | 8.8 | AzuraCast before 0.23.8 contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run … | Sep 27, 2026 |
| CVE-2026-100851 | HIGH | 7.6 | AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to … | Sep 27, 2026 |
| CVE-2026-100850 | HIGH | 7.7 | AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote playlist fetch (backend/src/Radio/AutoDJ/QueueBuilder.php, getMediaFromRemoteUrl()). A user with the … | Sep 27, 2026 |
| CVE-2026-100849 | HIGH | 7.1 | AzuraCast is a self-hosted web radio management suite. In AzuraCast before 0.23.8, the station webhook URL validation in AbstractConnector::getValidUrl() (backend/src/Webhook/Connector/AbstractConnector.php), used by the Generic and … | Sep 27, 2026 |
| CVE-2026-100848 | HIGH | 7.1 | AzuraCast (Composer package azuracast/azuracast) before 0.23.8 validates a station's "Remote Relay" URL only for URL syntax and an http/https scheme (Utilities\Urls::parseUserUrl, used by StationRemote::getUrlAsUri) and … | Sep 27, 2026 |
| CVE-2026-100847 | HIGH | 7.5 | AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter … | Sep 27, 2026 |
| CVE-2026-100846 | HIGH | 7.6 | MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its … | Sep 27, 2026 |
| CVE-2026-100845 | HIGH | 7.8 | MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with allow_pickle=True when loading .npy and .npz files. Attackers … | Sep 27, 2026 |
| CVE-2026-100844 | HIGH | 8.4 | MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner). User-controlled values taken from the YAML configuration file (notably dataset_name_or_id) and … | Sep 27, 2026 |
| CVE-2026-100843 | HIGH | 7.8 | MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserialization in monai/auto3dseg/utils.py. Attackers can craft malicious … | Sep 27, 2026 |
| CVE-2026-100842 | HIGH | 7.0 | MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. The function validates shape expressions with a helper that walks the AST and … | Sep 27, 2026 |