Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54367
Total
4306
Critical
16164
High
15850
Medium
CVE ID Severity Score Description Published
CVE-2026-100746 HIGH 7.3 A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /webhooks/source/github/redirect of the component GitHub App Setup … Sep 27, 2026
CVE-2026-100865 HIGH 8.8 Heym before 0.0.53 evaluates workflow condition expressions using Python's eval() with insufficient sandboxing in the workflow executor service. Authenticated users can edit workflow condition nodes … Sep 27, 2026
CVE-2026-100864 HIGH 8.8 heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback resolver that allows authenticated users to execute arbitrary Python … Sep 27, 2026
CVE-2026-100863 MEDIUM 5.0 Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both remediated in app/services/ssrf_guard.py in 0.0.91. First, the LLM image-edit input loader … Sep 27, 2026
CVE-2026-100862 MEDIUM 4.9 heym, a workflow automation platform, stores and returns multiple capability secrets in plaintext in versions prior to 0.0.91. Affected secrets include webhook header-auth values (returned … Sep 27, 2026
CVE-2026-100861 MEDIUM 5.0 heym before 0.0.105 fails to apply egress guards to integration services that use credential-supplied base URLs, allowing authenticated users to bypass SSRF protections. Attackers can … Sep 27, 2026
CVE-2026-100860 MEDIUM 5.5 heym before 0.0.105 does not act on the result of the credential authorization lookup in the Redis workflow node (backend/app/services/node_execution/nodes/redis_node.py). When _get_accessible_credential returns None — … Sep 27, 2026
CVE-2026-100859 MEDIUM 6.5 Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that allows collaborators with shared credential access to exfiltrate the credential owner's … Sep 27, 2026
CVE-2026-100858 MEDIUM 6.8 heym before 0.0.109 contains a server-side request forgery vulnerability in the Slack, Discord, and Crawler workflow nodes. These nodes issue HTTP requests to URLs taken … Sep 27, 2026
CVE-2026-100857 HIGH 8.0 AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media … Sep 27, 2026
CVE-2026-100856 HIGH 8.8 AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete migration from the vulnerable cleanUpString method to toRawString. … Sep 27, 2026
CVE-2026-100855 MEDIUM 6.5 AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station/{station_id}/file/{id}/play endpoint that allows authenticated users to download media files from any station. … Sep 27, 2026
CVE-2026-100854 MEDIUM 6.3 AzuraCast before 0.23.6 lacks RequireInternalConnection middleware on the Liquidsoap API endpoint and incorrectly derives the AutoDJ flag from header presence rather than validated value. Users … Sep 27, 2026
CVE-2026-100853 MEDIUM 5.9 In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allowing unauthenticated users to download media files excluded from On-Demand-enabled … Sep 27, 2026
CVE-2026-100852 HIGH 8.8 AzuraCast before 0.23.8 contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run … Sep 27, 2026
CVE-2026-100851 HIGH 7.6 AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to … Sep 27, 2026
CVE-2026-100850 HIGH 7.7 AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote playlist fetch (backend/src/Radio/AutoDJ/QueueBuilder.php, getMediaFromRemoteUrl()). A user with the … Sep 27, 2026
CVE-2026-100849 HIGH 7.1 AzuraCast is a self-hosted web radio management suite. In AzuraCast before 0.23.8, the station webhook URL validation in AbstractConnector::getValidUrl() (backend/src/Webhook/Connector/AbstractConnector.php), used by the Generic and … Sep 27, 2026
CVE-2026-100848 HIGH 7.1 AzuraCast (Composer package azuracast/azuracast) before 0.23.8 validates a station's "Remote Relay" URL only for URL syntax and an http/https scheme (Utilities\Urls::parseUserUrl, used by StationRemote::getUrlAsUri) and … Sep 27, 2026
CVE-2026-100847 HIGH 7.5 AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter … Sep 27, 2026
CVE-2026-100846 HIGH 7.6 MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its … Sep 27, 2026
CVE-2026-100845 HIGH 7.8 MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with allow_pickle=True when loading .npy and .npz files. Attackers … Sep 27, 2026
CVE-2026-100844 HIGH 8.4 MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner). User-controlled values taken from the YAML configuration file (notably dataset_name_or_id) and … Sep 27, 2026
CVE-2026-100843 HIGH 7.8 MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserialization in monai/auto3dseg/utils.py. Attackers can craft malicious … Sep 27, 2026
CVE-2026-100842 HIGH 7.0 MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. The function validates shape expressions with a helper that walks the AST and … Sep 27, 2026