Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 25 June 2026

RSS

1250 vulnerabilities published on 25 June 2026

Severity:
Daan.Dev OMGF Pro allows using malicious files
CVE-2026-57700
An attacker can upload malicious files to a Daan.Dev OMGF Pro server, potentially causing harm. This issue affects versions 5.2.6 and below of OMGF Pro. To protect your system, update to the latest ve...
10.0
Apache Kvrocks Heap Overflow When Parsing JSON Data
CVE-2026-46752
Apache Kvrocks versions 2.0.4 through 2.15.0 have a bug that can cause the system to run out of memory when parsing JSON data. This could lead to system crashes or instability. To fix this issue, upgr...
10.0
Lemur: AWS IAM and PKI Key Compromise via SSO
GHSA-v2wp-frmc-5q3v CVE-2026-55166 PYSEC-2026-384
A user with a valid SSO account can access and steal AWS IAM credentials and permanent TLS private keys from a Lemur installation. This can happen if Lemur trusts the user's corporate SSO account or a...
9.9
Debian Linux: Unauthenticated File Access via Samba
DEBIAN-CVE-2026-56786
A vulnerability in Debian's Samba package allows attackers to access files on a system without a password. This could potentially lead to unauthorized access to sensitive data. Debian users should upd...
9.9
Hydra - NTLM Authentication Handler Stack Overflow Risk
CVE-2026-56766
A malicious server can send a fake login request to Hydra, causing it to crash or run unauthorized code. This affects Hydra's ability to securely test login credentials. Update to the latest version o...
9.9
Widget Options <= 4.2.3: Remote Code Execution via Contributor Input
CVE-2026-54823
An attacker can execute malicious code on your site if a contributor uploads a malicious file. This affects Widget Options plugin versions 4.2.3 and earlier. To fix this, update to the latest version ...
9.9
Red Hat Hardened Images RPMs Update Fixes Security Flaws
RHSA-2026:25145
Red Hat has released an update for their Hardened Images RPMs, which includes bug fixes and security enhancements to prevent potential attacks and improve overall security. This update is recommended ...
9.9
Flowise: Unauthenticated File Writing to Filesystem
CVE-2025-71338
Flowise's document-store API endpoint allows unauthorized users to write files to the system. This could allow attackers to overwrite critical system files, potentially leading to remote code executio...
10.0
Flowise Custom MCP feature allows attackers to execute OS commands
CVE-2025-71336
Flowise versions 2.2.7-patch.1 and earlier are at risk of attackers executing arbitrary OS commands on the system. This is because the software's security settings are not strong enough, and an attack...
9.3
Flowise versions 2.2.8 and earlier allow unauthorized file access
CVE-2025-71334
An attacker can access or write any file on your system without permission by exploiting a weakness in the way Flowise handles file paths. This could potentially allow them to execute malicious code. ...
9.3
Flowise 2.2.4 allows attackers to upload malicious files
CVE-2025-71333
Flowise through version 2.2.4 has a security flaw that lets attackers upload files to any directory on the server without needing a password. This could allow them to take control of the server or exe...
9.3
TLS 1.3 KeyShare Handling Error in OpenSSL
CVE-2026-7531
A specific type of malicious server can cause OpenSSL to use memory that has already been freed, potentially leading to security issues. This is related to a previously fixed issue and requires furthe...
2.3
Cursor 3.0 or earlier: Malicious Agent Can Write Outside Workspace
CVE-2026-50549
A malicious agent in Cursor can write files outside the workspace, potentially allowing an attacker to run arbitrary code on your system. This is fixed in version 3.0, so update to that version or lat...
9.3
Cursor AI Editor: Unrestricted File Access
CVE-2026-50548
Prior to Cursor version 3.0, a security flaw allowed a malicious AI agent to write files outside the intended workspace. This could lead to unauthorized code execution. Users should update to Cursor v...
9.3
RTKLIB out-of-bounds write in decode_type1033 function
UBUNTU-CVE-2026-56786
A bug in RTKLIB's decode_type1033 function allows an attacker to corrupt the program's memory, potentially causing the program to crash or run malicious code. This affects RTKLIB versions up to 2.4.3....
9.9
RTKLIB versions 2.4.3 and below: Out-of-bounds write risk in decode_type1033 function
CVE-2026-56786
RTKLIB, a software library used for GPS and GLONASS data processing, has a security flaw that could allow an attacker to corrupt data and potentially take control of the system. This issue affects ver...
9.3
Malicious SOCKS5 Proxy Can Crash or Execute Code on socat
ALPINE-CVE-2026-56123
Versions 1.8.0.0 to 1.8.1.1 of socat are affected. A malicious SOCKS5 proxy server can potentially crash the system or execute unauthorized code. Update to a fixed version to mitigate the risk.
9.4
Socat Versions 1.8.0.0-1.8.1.1 Allow Malicious SOCKS5 Proxy Server to Crash
DEBIAN-CVE-2026-56123
A security issue affects older versions of Socat, a tool used to establish network connections. If exploited, a malicious SOCKS5 proxy server could cause the Socat process to crash, potentially leadin...
9.4
Socat Versions 1.8.0.0 to 1.8.1.1 Allow Malicious Proxy Server Overwrite
UBUNTU-CVE-2026-56123
A malicious SOCKS5 proxy server can overwrite memory on a vulnerable system. This could allow the attacker to take control of the system or disrupt its normal operation. Update Socat to a version 1.8....
9.4
rootio-sqlite3: Unauthenticated SQL Injection in Root
ROOT-OS-DEBIAN-11-CVE-2025-6965
The rootio-sqlite3 package in Root's Debian 11 distribution has a security issue that allows attackers to execute unauthorized SQL commands. This could lead to sensitive data being accessed or modifie...
9.8
Dell Wyse Management Suite accepts untrusted data from internet
CVE-2026-41120
Versions prior to WMS 5.5 HF1 of Dell Wyse Management Suite may allow an attacker with remote access to run malicious code on the system. This could happen if an attacker tricks the system into accept...
9.8
Linux Kernel TCP Connection Underflow Risk Fixed
CVE-2026-53260
A bug in the Linux kernel's TCP connection handling has been fixed. This bug could have caused a connection to be closed unexpectedly, potentially leading to data loss or system instability. The fix i...
9.8
Linux Kernel: Ethernet Driver Memory Leak Risk
CVE-2026-53247
A Linux kernel vulnerability has been fixed in an Ethernet driver, which could cause a memory leak. This issue affects Linux systems using certain Ethernet hardware. To fix this, the driver has been u...
9.8
Linux Kernel: SCTP Server Memory Corruption Risk
CVE-2026-53246
A bug in the Linux kernel's SCTP server could allow an attacker to access memory outside of its intended area, potentially causing system instability or crashes. This issue has been fixed, so no actio...
9.8
Linux Kernel: IPv6 Header Data Corruption Risk
CVE-2026-53228
A bug in the Linux kernel's IPv6 handling could cause data corruption. This has been fixed in the latest update, so it's no longer a concern. If you're using the Linux kernel, you should update to the...
9.8