2026 CVE Vulnerabilities

65,524 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-100856HIGH8.8AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete mig...
CVE-2026-100855MEDIUM6.5AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station/{station_id}/file/{id}...
CVE-2026-100854MEDIUM6.3AzuraCast before 0.23.6 lacks RequireInternalConnection middleware on the Liquidsoap API endpoint and incorrectly derive...
CVE-2026-100853MEDIUM5.9In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allow...
CVE-2026-100852HIGH8.8AzuraCast before 0.23.8 contains a command injection vulnerability in the Liquidsoap config generation for live recordin...
CVE-2026-100851HIGH7.6AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint...
CVE-2026-100850HIGH7.7AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote pl...
CVE-2026-100849HIGH7.1AzuraCast is a self-hosted web radio management suite. In AzuraCast before 0.23.8, the station webhook URL validation in...
CVE-2026-100848HIGH7.1AzuraCast (Composer package azuracast/azuracast) before 0.23.8 validates a station's "Remote Relay" URL only for URL syn...
CVE-2026-100847HIGH7.5AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListA...
CVE-2026-100846HIGH7.6MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/...
CVE-2026-100845HIGH7.8MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses n...
CVE-2026-100844HIGH8.4MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_run...
CVE-2026-100843HIGH7.8MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsa...
CVE-2026-100842HIGH7MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. Th...
CVE-2026-100841HIGH7.8In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weight...
CVE-2026-100840HIGH7.8MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _tar...
CVE-2026-100839HIGH8.4Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML hand...
CVE-2026-100838HIGH8.1Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generate...
CVE-2026-100837LOW3.7Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration...
CVE-2026-100836MEDIUM4.3Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSO...
CVE-2026-100835HIGH7.4Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report ...
CVE-2026-100834MEDIUM5.9http4k's Digest authentication module (org.http4k:http4k-security-digest) before versions 6.48.0.0, 5.42.0.0 and 4.51.0....
CVE-2026-100833HIGH8.2Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all containe...
CVE-2026-100745MEDIUM6.3A vulnerability has been found in Edimax BR-6428nC 1.16. The impacted element is an unknown function of the file /goform...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now