Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 24 June 2026

RSS

1495 vulnerabilities published on 24 June 2026

Severity:
GV-I/O Box 4E: Unsecured Service Allows Network Access
CVE-2026-12848
The GV-I/O Box 4E has a service that listens for messages from any user on the network, allowing unauthorized access. This could potentially be exploited by an attacker to take control of the device. ...
10.0
GV-I/O Box 4E: Unsecured Service Allows Network Access
CVE-2026-12847
The GV-I/O Box 4E has a service that listens for network messages without proper security. This allows anyone on the network to interact with the device and potentially cause harm. You should ensure t...
10.0
GV-I/O Box 4E: Unauthorized Network Access and Data Overflow
CVE-2026-12846
The GV-I/O Box 4E has a service that listens for incoming network messages without a password. This allows anyone on the network to interact with the device. Additionally, the device is vulnerable to ...
10.0
GV-I/O Box 4E: Unsecured Service Allows Network Access
CVE-2026-12485
The GV-I/O Box 4E has a service running by default that can be accessed by anyone on the network. This allows an attacker to potentially interact with the device and cause unintended behavior. To miti...
10.0
Cacti graph view has SQL injection vulnerability
DEBIAN-CVE-2026-39955
Cacti versions 1.2.30 and earlier have a security issue that allows attackers to inject malicious SQL code before logging in. This could potentially allow unauthorized access to sensitive data. Update...
9.8
Cacti versions 1.2.30 and prior allow unauthorized access
CVE-2026-39955
Cacti, a performance management tool, has a security flaw that could let attackers access sensitive data without proper authorization. This issue has been fixed in version 1.2.31, so it's recommended ...
9.8
Cacti versions 1.2.30 and prior allow SQL injection
CVE-2026-39948
An attacker can inject malicious SQL code without needing a password, potentially compromising the database and making it unavailable. This issue has been fixed in version 1.2.31, so update to the lat...
9.3
Cacti: Unauthenticated SQL Injection via rfilter Request Parameter
DEBIAN-CVE-2026-39948
Cacti versions 1.2.30 and earlier have a security flaw that allows an attacker to access sensitive data in the database without a password. This is a serious issue because it could lead to unauthorize...
9.8
Cacti versions 1.2.30 and prior allow unauthorized data access
CVE-2026-39938
Cacti, a performance and fault management tool, has a security issue that allows unauthorized users to access sensitive data. This issue affects versions 1.2.30 and earlier, but it has been fixed in v...
9.8
Cacti: Unauthenticated Access to Sensitive Files
DEBIAN-CVE-2026-39938
Cacti, an open-source performance monitoring tool, allows unauthorized access to sensitive files in versions prior to 1.2.31. This vulnerability could allow attackers to view or modify critical system...
9.8
Cacti versions 1.2.30 and prior: Unauthenticated SQL Injection
CVE-2026-39893
Cacti's performance monitoring tool has a security flaw in versions 1.2.30 and earlier. An attacker can inject malicious code into the system without needing a login, potentially allowing them to acce...
9.8
Cacti versions 1.2.30 and prior allow SQL injection attacks
DEBIAN-CVE-2026-39893
Cacti, a tool for monitoring network performance, is vulnerable to a SQL injection attack if a guest user is enabled. An attacker can exploit this vulnerability to access sensitive data. To protect yo...
9.8
Debian Linux: Unauthenticated Remote Code Execution
DEBIAN-CVE-2026-49980
Debian Linux users may be at risk of remote code execution attacks if they use certain network services. This means that attackers could potentially take control of affected systems without needing a ...
9.8
Debian Linux: Unauthenticated Remote Code Execution
DEBIAN-CVE-2026-54906
A security issue in Debian Linux allows attackers to execute malicious code on a system without needing a password. This means that if a hacker can exploit this vulnerability, they could gain control ...
9.8
Linux Kernel BCM Genet Driver Off-By-One Error Fix
CVE-2026-53088
A bug in the Linux kernel's BCM Genet driver has been fixed. This bug could have caused the driver to incorrectly clean up memory, potentially leading to crashes or data corruption. The fix ensures th...
9.8
Linux bcmgenet Network Driver Queue Timeout Fix
CVE-2026-53086
A bug in the bcmgenet network driver was causing issues with network queues. This fix ensures that only the affected queue is restarted when a timeout occurs, preventing other queues from being disrup...
9.8
Linux Kernel: Heavy Load Causes Data Access Error
CVE-2026-53055
A bug in the Linux kernel's encryption handling could cause a data access error when the system is under heavy load. This could lead to system crashes or data corruption. To fix this, the Linux kernel...
9.8
Linux kernel: Data loss from concurrent transactions
CVE-2026-53049
A bug in the Linux kernel's GFS2 file system could cause data loss when multiple transactions happen at the same time. This has been fixed in a recent update, so it's no longer a concern. If you're us...
9.8
Linux Kernel ksmbd Vulnerability Fixed: Qualcomm Crypto Engine Crash
CVE-2026-53046
A security issue was fixed in the Linux kernel's ksmbd component, which handles encryption for certain file transfers. The fix prevents a potential crash when using the Qualcomm Crypto Engine for encr...
9.8
Linux Kernel: Tegra Memory Timing DLL Enable Fix
CVE-2026-53045
A bug in the Linux kernel's memory timing settings for Tegra devices has been fixed. This bug could have caused memory issues, potentially leading to system crashes or data corruption. The fix ensures...
9.8
Linux kernel ksmbd SMB2 reconnect causes file descriptor leak
CVE-2026-53010
A bug in the Linux kernel's ksmbd SMB2 reconnect process could cause a file descriptor to be deleted too early, leading to data loss. This issue has been fixed in a recent update. Update your Linux ke...
9.8
Linux Kernel IPv6 Handling Bug Fixed
CVE-2026-53006
A bug in the Linux kernel's IPv6 handling has been fixed, which could potentially allow attackers to access memory they shouldn't. This bug has been resolved, but it's essential to keep your Linux sys...
9.8
Linux Kernel: Potential Data Corruption in SIP Processing
CVE-2026-53002
A vulnerability in the Linux kernel's SIP processing could allow an attacker to write data to an unintended location, potentially leading to system instability or crashes. This issue has been fixed by...
9.8
Linux Kernel: Double-Free Bug Fixed in TIPC Buffer Handling
CVE-2026-52993
A bug in the Linux kernel's TIPC (Transparent Inter-Process Communication) buffer handling has been fixed. This bug could have led to a double-free error, causing system instability or crashes. Linux ...
9.8
Linux Kernel: Uninitialized Data in NVMET-TCP Socket Receiving Loop
CVE-2026-52989
A bug in the Linux kernel's NVMET-TCP module can cause the system to read incorrect network data. This can lead to data corruption or system crashes. To fix this issue, software developers need to pro...
9.8