Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 27 June 2026

RSS

534 vulnerabilities published on 27 June 2026

Severity:
Apache HTTP Server Remote File Disclosure in Log Files
BELL-CVE-2026-53247
Apache HTTP Server's log files can expose sensitive information, including user data and system paths. This vulnerability allows attackers to access and potentially exploit this sensitive information....
9.8
Apache HTTP Server Unsecured File Access on Windows
BELL-CVE-2026-53216
Apache HTTP Server on Windows allows unauthorized access to files on the server, which can lead to data theft or system compromise. This vulnerability affects servers running Apache HTTP Server on Win...
9.8
WordPress Cross-Site Scripting (XSS) in Plugin
BELL-CVE-2026-53215
A security flaw in a popular WordPress plugin can allow hackers to inject malicious code into websites, potentially stealing user data or taking control of the site. This issue affects websites using ...
9.8
Apache HTTP Server Remote File Access on Windows
BELL-CVE-2026-53175
Apache's Windows version allows unauthorized access to files due to a misconfigured Windows service. This can happen when an attacker sends a specific request to the server, which could potentially le...
9.8
Apache HTTP Server Uncontrolled Memory Access in mod_proxy_fcgi
BELL-CVE-2026-53151
Apache's mod_proxy_fcgi module in the HTTP Server has a bug that can cause the server to access memory it shouldn't, potentially leading to crashes or data corruption. This affects servers that use mo...
9.8
Apache HTTP Server Cross-Site Scripting (XSS) in Windows
BELL-CVE-2026-53221
The Apache HTTP Server on Windows may allow an attacker to inject malicious code into a website, potentially stealing user data or taking control of the website. This affects Windows users who use the...
9.8
Apache HTTP Server Remote Code Execution via HTTP Request
BELL-CVE-2026-53246
Apache HTTP Server versions 2.4.53 and earlier allow an attacker to execute malicious code on the server by sending a specially crafted HTTP request. This can lead to unauthorized access to the server...
9.8
Adobe Reader PDF Parsing Code Execution Vulnerability
BELL-CVE-2026-53228
Adobe Reader, a popular PDF viewer, contains a vulnerability that could allow hackers to execute malicious code on a user's device. This could lead to unauthorized access to sensitive information or t...
9.8
Apache HTTP Server Remote Code Execution
BELL-CVE-2026-53176
Apache HTTP Server versions 2.4.52 and earlier contain a vulnerability that allows an attacker to execute arbitrary code on a server. This could happen if a malicious user sends a specially crafted HT...
9.8
WordPress Invoice Generator Plugin Allows Email Hijacking
CVE-2026-12415
The WordPress Invoice Generator plugin has a security flaw that lets attackers change the email address of any user, including administrators. This can be used to gain access to sensitive accounts. Up...
9.8
Apache HTTP Server Remote Code Execution via HTTP Request
BELL-CVE-2026-53131
Apache HTTP Server may allow attackers to execute arbitrary code on the server when processing specially crafted HTTP requests. This is a significant risk because attackers can gain control of the ser...
9.4
Apache HTTP Server Remote File Disclosure in mod_proxy
BELL-CVE-2026-53186
Apache HTTP Server's mod_proxy module allows attackers to access sensitive files on a server by manipulating HTTP requests. This can lead to unauthorized access to sensitive data, potentially compromi...
9.1
Apache HTTP Server Remote Code Execution Vulnerability
BELL-CVE-2026-53225
Apache HTTP Server versions 2.4.51 and earlier may allow attackers to execute arbitrary code on the server. This could happen if an attacker sends a specially crafted request to the server. To protect...
9.1
Apache HTTP Server Unauthenticated File Disclosure
BELL-CVE-2026-53224
The Apache HTTP Server is vulnerable to a file disclosure bug. This means that an attacker can access sensitive files on a server without needing a password. Businesses should update their Apache HTTP...
9.1
Adobe Reader Unsecured File Handling
BELL-CVE-2026-53266
Adobe Reader, a popular PDF viewer, has a security flaw that can allow an attacker to read or modify sensitive files on your computer. This could lead to unauthorized access to your data. To stay safe...
8.8
Apache HTTP Server Denial of Service Vulnerability
BELL-CVE-2026-53248
Apache HTTP Server versions 2.4.52 and earlier have a vulnerability that could allow an attacker to crash the server, causing it to stop working temporarily. This could potentially impact the availabi...
8.8
Apache HTTP Server Unauthenticated Directory Traversal
BELL-CVE-2026-53240
The Apache HTTP Server is affected by a vulnerability that allows an attacker to access sensitive files on the server without authentication. This could potentially lead to data exposure and unauthori...
8.8
Apache HTTP Server Remote File Access in Windows
BELL-CVE-2026-53198
Apache's HTTP Server for Windows has a security flaw that allows an attacker to access any file on the server. This could happen if an attacker sends a specially crafted request to the server. To fix ...
8.8
Apache HTTP Server Unauthenticated Remote Code Execution
BELL-CVE-2026-53277
Apache HTTP Server's configuration file parser has a vulnerability that allows attackers to execute arbitrary code on a server without needing a password. This could allow hackers to take control of a...
8.8
Apache HTTP Server Uncontrolled Memory Allocation
BELL-CVE-2026-53232
Apache HTTP Server has a vulnerability that allows an attacker to crash the server or potentially execute malicious code. This affects servers that use Apache HTTP Server to handle web requests. To mi...
8.8
CVE-2026-53200 does not affect BellSoft software
BELL-CVE-2026-53200
8.8
Apache HTTP Server Cross-Site Scripting in PHP Handler
BELL-CVE-2026-53188
Apache HTTP Server's PHP handler is vulnerable to cross-site scripting attacks. This means an attacker could inject malicious code into a website, potentially stealing user data or taking control of t...
8.8
Apache HTTP Server Unauthenticated Remote Code Execution
BELL-CVE-2026-53275
Apache HTTP Server versions 2.4.52 and earlier allow an attacker to execute malicious code on a server without needing a password. This can happen if a user visits a specially crafted website. To prot...
8.8
Zephyr's IP Socket Receive Buffer Overflow
CVE-2026-10643
Zephyr's IP socket receive function does not properly check the size of a user-supplied buffer, allowing an attacker to cause a buffer overflow. This can lead to data corruption and potentially allow ...
8.7
Apache HTTP Server Unrestricted File Access on Windows
BELL-CVE-2026-53230
Apache HTTP Server on Windows may allow an attacker to read or write files outside the intended directory. This can happen if an attacker sends a specially crafted request to the server. To fix this, ...
8.7