Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 16 April 2026

RSS

927 vulnerabilities published on 16 April 2026

Severity:
rootio-python3.11: Untrusted Code Execution Through Malicious Package
ROOT-OS-DEBIAN-12-CVE-2025-11468
An update has been released for rootio-python3.11 to prevent malicious packages from executing unauthorized code on your server. This update is crucial for maintaining the security of your system. Upd...
rootio-python3.11: Unauthenticated Remote Code Execution Risk
ROOT-OS-DEBIAN-12-CVE-2025-6069
The rootio-python3.11 package in Root Debian 12 is vulnerable to a security issue that allows an attacker to potentially run malicious code on the system without needing a password. This could allow a...
Rootio Python 3.11: Unpatched Code Execution
ROOT-OS-DEBIAN-12-CVE-2025-8291
A security patch has been released for Rootio Python 3.11, a popular Python implementation used by Root. This patch fixes a previously unaddressed issue that, if exploited, could allow malicious code ...
rootio-python3.11: Unrestricted File Access via Specially Crafted Input
ROOT-OS-DEBIAN-12-CVE-2025-13462
The rootio-python3.11 package on Root:Debian:12 has a security issue that could allow an attacker to access files on your system without permission. This could lead to sensitive data being accessed or...
rootio-python3.11: Unauthenticated Code Execution via HTTP Request
ROOT-OS-DEBIAN-12-CVE-2026-6100
The rootio-python3.11 package had a security issue that could allow an attacker to execute code on your system without a password. This was fixed by the Root team, so you should update to the latest v...
rootio-python3.11: Unrestricted Arbitrary Code Execution
ROOT-OS-DEBIAN-12-CVE-2026-4224
The Rootio package for Python 3.11 has a known vulnerability which could allow an attacker to run arbitrary code on a system. This could potentially allow an attacker to take control of the system. Ro...
rootio-python3.11: Unauthenticated Remote Code Execution
ROOT-OS-DEBIAN-12-CVE-2025-15366
An attacker can execute arbitrary code on a system using rootio-python3.11 without needing a password. This affects Root users who have installed the rootio-python3.11 package on Debian 12. To protect...
rootio-python3.11: Uncontrolled Memory Access in Root Environment
ROOT-OS-DEBIAN-12-CVE-2026-3479
An issue in the rootio-python3.11 package for Root:Debian:12 could allow an attacker to potentially access sensitive information or cause a denial of service. This has been fixed by Root in a software...
rootio-python3.11: Malicious code execution via Python script
ROOT-OS-DEBIAN-12-CVE-2025-13836
A security issue has been fixed in the rootio-python3.11 package, which allows an attacker to run malicious code if they can inject a specially crafted Python script. This is a serious issue for users...
rootio-python3.11: Unauthenticated Command Execution
ROOT-OS-DEBIAN-12-CVE-2025-15282
The rootio-python3.11 package for Debian 12 contains a vulnerability that allows an attacker to execute arbitrary commands on the system without a password. This means an attacker could potentially ta...
rootio-python3.11: Data Exposure in Python Library
ROOT-OS-DEBIAN-12-CVE-2026-1299
A bug in the rootio-python3.11 package could potentially allow unauthorized access to sensitive data. This issue has been fixed by the developers, and updated versions are available. Users of Root:Deb...
Vehicle Parking Area Management System SQL Injection
CVE-2026-37344
A security weakness in the Vehicle Parking Area Management System allows an attacker to manipulate database queries, potentially allowing unauthorized access or data theft. This affects the 'manage_lo...
Vehicle Parking Area Management System SQL Injection
CVE-2026-37343
The Vehicle Parking Area Management System is vulnerable to a SQL Injection attack, which allows an attacker to manipulate the system's database. This could potentially allow unauthorized access to se...
SQL Injection in Vehicle Parking Area Management System
CVE-2026-37342
The Vehicle Parking Area Management System is vulnerable to an attack that could allow an attacker to access sensitive data. This could happen if an attacker sends malicious input to the system, poten...
SQL Injection in Vehicle Parking Area Management System puts data at risk
CVE-2026-37341
The Vehicle Parking Area Management System version 1.0 has a security weakness that could allow attackers to access sensitive data. If exploited, this could lead to unauthorized access to user informa...
Simple Music Cloud Community System SQL Injection Vulnerability
CVE-2026-37340
The Simple Music Cloud Community System version 1.0 has a security flaw that could allow an attacker to access or modify sensitive data. This issue can be exploited through the edit_music.php file, wh...
Simple Music Cloud Community System SQL Injection Vulnerability
CVE-2026-37339
A security weakness in the Simple Music Cloud Community System allows attackers to access or modify sensitive data. This affects the view_genre.php file in the system. To protect your data, update to ...
Rust 1.93: Denial of Service via Malicious Network Packets
Rust 1.93 has a security update to prevent a denial of service attack through specially crafted network packets. This update also resolves a build issue that could prevent some programs from compiling...
Rust 1.93: Denial of Service in QUIC Initial Packet
SUSE-SU-2026:1415-1
A security update for Rust 1.93 fixes a vulnerability that could allow a malicious actor to crash your system. This update also resolves an issue that could prevent some projects from building. We rec...
Update for shim fixes multiple security issues
SUSE-SU-2026:1414-1
A security update is available for shim, a tool used to manage secure boot on computers. This update fixes several potential security issues, including a flaw that could allow an attacker to bypass ce...
Debian OpenSSL Weak Signature Verification Allows Man-in-the-Middle Attacks
DEBIAN-CVE-2026-41035
A vulnerability in Debian's OpenSSL package allows an attacker to intercept and manipulate sensitive data, such as encrypted communications, by exploiting a weakness in the way signatures are verified...
VMware UEFI Firmware Update Fixes Cryptographic Vulnerability
SUSE-SU-2026:1413-1
This update addresses a vulnerability in the mbedtls library used in VMware UEFI Firmware, which could allow an attacker to exploit a timing-based attack to bypass encryption. This could potentially a...
Invalid Vulnerability Report: Do Not Use
CVE-2026-5968
A mistake was made in the processing of a security report and it should not be considered valid. This means that there is no actual risk to address. No action is needed.
Python urllib3 Update Fixes Security Issues with Decompression
SUSE-SU-2026:1412-1
This update for Python urllib3 fixes security issues that could cause a program to consume excessive resources and potentially lead to a denial of service. It's recommended to update Python urllib3 to...
Terraform Providers: Security Update to Prevent Data Corruption and Authorization Bypass
SUSE-SU-2026:1411-1
This update fixes two security issues in Terraform's providers for local storage, randomness, and TLS. If not patched, these issues could allow attackers to consume corrupted files or bypass authoriza...