2026 CVE Vulnerabilities
65,524 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100856 | HIGH | 8.8 | — | Sep 27, 2026 | AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete mig... |
| CVE-2026-100855 | MEDIUM | 6.5 | — | Sep 27, 2026 | AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station/{station_id}/file/{id}... |
| CVE-2026-100854 | MEDIUM | 6.3 | — | Sep 27, 2026 | AzuraCast before 0.23.6 lacks RequireInternalConnection middleware on the Liquidsoap API endpoint and incorrectly derive... |
| CVE-2026-100853 | MEDIUM | 5.9 | — | Sep 27, 2026 | In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allow... |
| CVE-2026-100852 | HIGH | 8.8 | — | Sep 27, 2026 | AzuraCast before 0.23.8 contains a command injection vulnerability in the Liquidsoap config generation for live recordin... |
| CVE-2026-100851 | HIGH | 7.6 | — | Sep 27, 2026 | AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint... |
| CVE-2026-100850 | HIGH | 7.7 | — | Sep 27, 2026 | AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote pl... |
| CVE-2026-100849 | HIGH | 7.1 | — | Sep 27, 2026 | AzuraCast is a self-hosted web radio management suite. In AzuraCast before 0.23.8, the station webhook URL validation in... |
| CVE-2026-100848 | HIGH | 7.1 | — | Sep 27, 2026 | AzuraCast (Composer package azuracast/azuracast) before 0.23.8 validates a station's "Remote Relay" URL only for URL syn... |
| CVE-2026-100847 | HIGH | 7.5 | — | Sep 27, 2026 | AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListA... |
| CVE-2026-100846 | HIGH | 7.6 | — | Sep 27, 2026 | MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/... |
| CVE-2026-100845 | HIGH | 7.8 | — | Sep 27, 2026 | MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses n... |
| CVE-2026-100844 | HIGH | 8.4 | — | Sep 27, 2026 | MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_run... |
| CVE-2026-100843 | HIGH | 7.8 | — | Sep 27, 2026 | MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsa... |
| CVE-2026-100842 | HIGH | 7 | — | Sep 27, 2026 | MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. Th... |
| CVE-2026-100841 | HIGH | 7.8 | — | Sep 27, 2026 | In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weight... |
| CVE-2026-100840 | HIGH | 7.8 | — | Sep 27, 2026 | MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _tar... |
| CVE-2026-100839 | HIGH | 8.4 | — | Sep 27, 2026 | Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML hand... |
| CVE-2026-100838 | HIGH | 8.1 | — | Sep 27, 2026 | Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generate... |
| CVE-2026-100837 | LOW | 3.7 | 0.2% | Sep 27, 2026 | Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration... |
| CVE-2026-100836 | MEDIUM | 4.3 | — | Sep 27, 2026 | Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSO... |
| CVE-2026-100835 | HIGH | 7.4 | — | Sep 27, 2026 | Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report ... |
| CVE-2026-100834 | MEDIUM | 5.9 | — | Sep 27, 2026 | http4k's Digest authentication module (org.http4k:http4k-security-digest) before versions 6.48.0.0, 5.42.0.0 and 4.51.0.... |
| CVE-2026-100833 | HIGH | 8.2 | 0.2% | Sep 27, 2026 | Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all containe... |
| CVE-2026-100745 | MEDIUM | 6.3 | — | Sep 27, 2026 | A vulnerability has been found in Edimax BR-6428nC 1.16. The impacted element is an unknown function of the file /goform... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now