Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 28 June 2026
RSS365 vulnerabilities published on 28 June 2026
Severity:
Gitea act_runner Docker Escalation with Privileged: False
CVE-2026-58053
Gitea's Docker workflow feature allows users to run jobs with elevated privileges, even when 'privileged' mode is disabled. This means a malicious user can potentially escape the job container and gai...
9.4
Joomla JoomCCK extension allows SQL injection
CVE-2026-49048
A Joomla extension called JoomCCK has a security flaw that can allow hackers to inject malicious SQL code into the website. This can lead to unauthorized access to sensitive data or even take control ...
8.7
Rocky Linux 8: pandoc table parsing flaw
RLSA-2022:5597
A security update is available for Rocky Linux 8 to fix a bug in the pandoc software that converts text formats. This bug could potentially allow an attacker to execute malicious code. We recommend up...
8.8
FFmpeg RASC Video Decoder Allows Memory Corruption
CVE-2026-58049
The FFmpeg RASC video decoder has a bug that can cause it to access memory outside its allowed space. This can happen when decoding a specially crafted video file. To stay safe, update to the latest v...
8.8
Debian Linux: Unprivileged user file system access
DEBIAN-CVE-2026-13500
A vulnerability in Debian Linux allows an attacker with limited privileges to access sensitive files on the system. This could potentially lead to unauthorized data access or system compromise. Debian...
8.4
WordPress Frontend File Manager Plugin deletes arbitrary files
CVE-2026-8095
The Frontend File Manager Plugin for WordPress, used in versions up to 23.6, allows attackers with Subscriber-level access to delete any file on the server, including sensitive files like the site's c...
8.1
Debian Linux: Unauthenticated Remote Code Execution
DEBIAN-CVE-2026-13503
An attacker can run malicious code on Debian Linux systems without needing a password. This is a serious security risk because it could allow an attacker to take control of a system. Debian has releas...
7.8
RustDesk: Unauthorized input injection through file transfer
CVE-2026-58056
RustDesk allows unauthorized access to keyboard, mouse, and screen capture functions when a file transfer is initiated. This means a user with limited permissions can potentially gain control of the c...
7.2
nghttp2 nghttpx - Malicious HTTP Requests Can Reach Intended Servers
CVE-2026-58055
A vulnerability in nghttp2's nghttpx proxy allows attackers to send malicious HTTP requests that can reach the intended servers, potentially compromising the security of your website or application. T...
7.6
libssh2 heap buffer overflow in publickey-subsystem
CVE-2026-58050
A malicious SSH server can cause a libssh2 client to crash or run malicious code. This affects libssh2 versions up to 1.11.1. To protect your system, update to a newer version of libssh2 that fixes th...
8.3
libssh2: Malicious SSH server can cause client memory overflow
UBUNTU-CVE-2026-58050
Libssh2, a library used for SSH connections, has a weakness that allows a malicious SSH server to potentially cause a memory overflow in a connecting client. This could lead to a security issue. Affec...
8.4
mysql 8.0: Multiple Security Risks Fixed
RLSA-2023:3087
This update fixes multiple security risks in MySQL 8.0, including vulnerabilities that could allow unauthorized access to sensitive data or disrupt database operations. It's essential to install this ...
7.5
Zephyr's DNS Resolver Allows Corrupted Data
CVE-2026-10646
Zephyr's DNS resolver can allow an attacker to corrupt data in memory. This happens when a network response is delivered to the resolver after it has finished using the memory. To protect against this...
7.4
ANTLR4 Grammar Action Block Handler Code Injection Risk
CVE-2026-13500
ANTLR4 users are at risk of code injection attacks if an attacker manipulates certain files. This could happen if an attacker has remote access to the system. It's recommended to update to the latest ...
5.5
yashpokharna2555 Restaurant Management System: Remote Password Reset Risk
CVE-2026-13498
An attacker can exploit a weakness in the password reset feature of the yashpokharna2555 Restaurant Management System, potentially allowing them to access sensitive data. This vulnerability can be exp...
5.5
SourceCodester Class and Exam Timetabling System SQL Injection Risk
CVE-2026-13488
An attacker can inject malicious SQL code into the system, potentially stealing or modifying sensitive data. This vulnerability affects the SourceCodester Class and Exam Timetabling System, which may ...
5.5
SourceCodester Class and Exam Timetabling System: SQL Injection via Remote Input
CVE-2026-13487
An unknown function in SourceCodester Class and Exam Timetabling System 1.0 is vulnerable to SQL injection attacks. This means that an attacker can potentially access sensitive data or disrupt the sys...
5.5
SourceCodester Class and Exam Timetabling System SQL Injection
CVE-2026-13486
A vulnerability in the SourceCodester Class and Exam Timetabling System allows an attacker to inject malicious SQL code, potentially exposing sensitive data. This issue can be exploited remotely, and ...
5.5
SourceCodester Class and Exam Timetabling System 1.0 SQL Injection Risk
CVE-2026-13485
A security risk has been discovered in SourceCodester Class and Exam Timetabling System version 1.0. This could allow an attacker to access or modify sensitive data remotely. To protect your system, u...
5.5
Adobe Acrobat: Heap Buffer Overflow in BMP Images
RLSA-2023:2589
Adobe Acrobat's autotrace feature can be exploited by malicious BMP images, potentially allowing an attacker to execute arbitrary code. This vulnerability affects users who use autotrace to convert im...
7.3
Adobe Illustrator autotrace heap-buffer overflow risk
RLSA-2023:3067
The autotrace feature in Adobe Illustrator can be exploited to cause the program to crash or behave unexpectedly. This issue can be triggered when the program is used to convert certain types of bitma...
7.3
MyBB 1.8.40: Limited Admins can assign full Admin rights
CVE-2026-58054
A limited Admin can accidentally or intentionally make a user an Admin, giving them too much power. This can happen when an Admin with limited permissions is allowed to create or edit user accounts. T...
8.6
Libssh2: Malicious SSH Server Can Cause Client Memory Overflow
DEBIAN-CVE-2026-58050
A weakness in Libssh2 allows a malicious SSH server to crash or take control of a client by overflowing its memory. This affects Libssh2 versions up to 1.11.1, and it's essential to update to the late...
8.4
Debian Linux Filesystem Corruption Due to Samba Misconfiguration
DEBIAN-CVE-2026-13501
A misconfiguration in Debian Linux's Samba package can cause data corruption on network file systems. This affects users who rely on shared files and folders across their network. To fix this issue, u...
6.9
7-Zip fails to protect Windows files from internet threats
DEBIAN-CVE-2026-58052
A security issue affects 7-Zip for Windows versions up to 26.02. When extracting certain types of files, it fails to protect the file from being modified by an attacker. This could allow an attacker t...
6.8