Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 23 June 2026

RSS

668 vulnerabilities published on 23 June 2026

Severity:
Traefik: Unauthenticated access to mTLS-protected services via HTTP/3
GHSA-9cr8-q42q-g8m7 CVE-2026-53622
A critical vulnerability in Traefik's HTTP/3 configuration can allow unauthenticated clients to access services protected by client certificate authentication. This is possible when HTTP/3 is enabled ...
7.8
motionEye Admin Password Theft via Path Traversal
GHSA-phv5-334h-mxcw
An attacker can steal the admin password from a motionEye installation by exploiting a path traversal vulnerability when the normal user password is left empty. This allows full admin access without a...
10.0
Budibase: Unauthenticated access to MongoDB and other databases
GHSA-8qv3-p479-cj62 CVE-2026-54350
An attacker can access and read all data in a Budibase app's database without needing a password. This is because of a mistake in how Budibase handles user input in its database queries. To fix this, ...
10.0
Gogs allows attackers to execute code on the server
GHSA-c39w-43gm-34h5 CVE-2026-52813
Gogs has a security weakness that allows an attacker to store and execute malicious code on the server. This can happen when an attacker creates a fake organization name that contains special characte...
10.0
UniFi OS: Malicious network access can access system files
CVE-2026-34909
UniFi OS devices have a security weakness that allows an attacker with network access to access sensitive files on the system. This could potentially be used to gain further access to the system. To p...
10.0 KEV
UniFi OS: Unauthorized changes to system configuration
CVE-2026-34908
This vulnerability affects UniFi OS devices. If left unpatched, a malicious actor with access to the network could make unauthorized changes to the system, potentially disrupting network operations. T...
10.0 KEV
Unifi OS Command Injection through Malicious Network Access
CVE-2026-34910
Unifi OS devices can be compromised if an attacker is on the same network. This could allow the attacker to execute unauthorized system commands. To protect your network, ensure you keep UniFi OS soft...
10.0 KEV
motionEye Admin Password Theft via Path Traversal
GHSA-phv5-334h-mxcw
An attacker can steal the admin password from motionEye installations that leave the user password empty. This can happen when an unauthenticated user exploits a path traversal vulnerability to read t...
9.9
Gogs allows authenticated users to take control of the server
GHSA-qf6p-p7ww-cwr9 CVE-2026-52806
A security issue in Gogs allows an authenticated user to take control of the server by creating a special pull request. This means they could access, modify, or steal data from other users' repositori...
9.9
motionEye: Unauthenticated Remote Code Execution
GHSA-qxvg-h7q2-hcxh
motionEye has a multi-stage vulnerability that allows attackers to execute code on the server without a password. This happens when a normal user's password is unset, or when an attacker gains access ...
9.8
Apache Tomcat: Important Security Patch Released for Remote Code Execution
ROOT-APP-MAVEN-CVE-2025-24813
A patch has been released for the Apache Tomcat library that prevents attackers from potentially running unauthorized code on your server. This affects systems running outdated versions of the library...
9.8
rootio-aom: Unsecured Data Access in Rootio-aom
ROOT-OS-DEBIAN-11-CVE-2023-6879
The rootio-aom package on Root:Debian:11 allows unauthorized access to sensitive data. This could lead to data breaches and unauthorized use of the data. Root has released patches for this issue, so i...
9.8
Expr-eval: Unrestricted JavaScript Execution via User Input
CVE-2026-12866
All versions of the expr-eval package are affected. This means an attacker could potentially run malicious code within your application if they can influence the input that expr-eval processes. Update...
9.2
Lantronix EDS5000 allows remote code execution through username field
CVE-2025-67038
Lantronix's EDS5000 2.1.0.0R3 has a security flaw that allows hackers to execute commands on the device by manipulating the username field when authentication fails. This means an attacker could poten...
9.8 KEV
Poweradmin DNS tool: Unauthenticated account takeover risk
CVE-2026-54588
The Poweradmin DNS tool has a security flaw that allows an attacker to take control of an account without knowing the password. This is because the tool doesn't properly check the source of some authe...
9.6
Event-Driven Ansible Websocket API Missing Authorization
CVE-2026-11807
An unauthorized user can access sensitive credentials of other users by sending a malicious message. This is a serious security risk because it can lead to unauthorized access to important systems and...
9.6
Capgo - Unauthorized Access to Other Organizations' Apps
CVE-2026-56222 GHSA-5r52-m8r9-7f8x
An attacker with admin privileges in one organization can access and modify apps from other organizations using Capgo before version 12.128.2. This is a serious issue because it allows unauthorized ac...
9.4
Red Hat OpenStack Platform 17.1 etcd Security Update
RHSA-2026:28047
An update is available for etcd in Red Hat OpenStack Platform 17.1. This update addresses a security issue that could allow an attacker to manipulate etcd data, potentially leading to data corruption ...
9.1
Red Hat osbuild-composer Update: Unauthenticated Access Risk
RHSA-2026:27856
An update is available for Red Hat's osbuild-composer, a tool for creating operating system images. This update addresses a security issue that could allow unauthorized access to the system. Businesse...
9.1
Gogs: Malicious File Upload Can Write Outside Repo
GHSA-89mr-xqfv-758m CVE-2026-52811
Gogs, a self-hosted Git platform, has a security issue that allows attackers with write access to a repository to upload files that can be written outside the repository's working directory. This coul...
9.0
Samba on Red Hat Linux: Remote Access Risk
RHSA-2026:28132
Samba, a software that allows Linux systems to share files and printers with Windows systems, has a security update available. This update fixes a vulnerability that could allow an attacker to access ...
9.0
Red Hat Samba Security Update: Remote Code Execution Risk
RHSA-2026:28058
Red Hat Samba, a software that allows Windows and Linux computers to share files and printers, has a security update. This update fixes a critical flaw that could allow an attacker to take control of ...
9.0
Samba for Linux: Unauthenticated Remote Code Execution
RHSA-2026:28057
A security update is available for Samba, a software that allows Linux computers to communicate with Windows computers. This update fixes a vulnerability that could allow an attacker to execute malici...
9.0
Samba Remote Code Execution Vulnerability on Linux Systems
RHSA-2026:28056
A vulnerability in Samba, a popular file and print sharing software, allows an attacker to execute malicious code on a Linux system remotely. This could potentially lead to unauthorized access to sens...
9.0
Red Hat Samba Security Update Exposes Passwords in Plain Text
RHSA-2026:28054
A security update is available for Red Hat Samba, a software that helps Windows computers connect to Linux servers. If not updated, an attacker could potentially intercept and read sensitive informati...
9.0