Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 29 June 2026
RSS541 vulnerabilities published on 29 June 2026
Severity:
SimpleHelp OIDC Authentication Bypass in Older Versions
CVE-2026-48558
Old versions of SimpleHelp allow hackers to access the system without a password. This happens when the system uses a specific authentication method. To fix this, update to the latest version of Simpl...
9.5
KEV
Paid Videochat Turnkey Site: Unrestricted File Deletion
CVE-2026-57331
Versions 7.4.8 and earlier of Paid Videochat Turnkey Site allow an attacker to delete any file on the server, potentially disrupting the site's functionality. This issue is particularly concerning bec...
9.9
Appsmith: Unauthenticated Access to Reverse Proxy API
CVE-2026-55454
BIT-appsmith-2026-55454
Appsmith's built-in reverse proxy had no password protection, allowing a malicious user to take control of the proxy and potentially harm the system. This issue has been fixed in version 2.1. Users sh...
9.9
AWS Load Balancer: HTTP/2 Bypass of WAF Inspection
CVE-2026-13763
Some AWS load balancers might not properly check requests if they use a new internet protocol. This can let hackers get past security rules. To fix this, make sure your load balancer is set to inspect...
7.9
AWS WAF may be bypassed by crafted HTTP/2 requests in CloudFront
CVE-2026-13762
AWS WAF managed rules might be bypassed if a hacker sends a special type of HTTP request. This issue has been fixed by AWS, so no action is needed from customers. Amazon CloudFront is a service that h...
7.9
Gorse before 0.5.10 allows unauthorized access to sensitive data
CVE-2026-56782
The Gorse software has a security flaw that allows attackers to access and potentially steal or delete sensitive user data without being authorized. This is a concern because it could lead to a data b...
9.3
rclone for Root:Go: Unauthorized File Access
ROOT-APP-GOBINARY-CVE-2026-41176
A security patch has been applied to rclone for Root:Go to prevent unauthorized access to files. This is important because it affects how Root:Go handles sensitive data. If you're using rclone for Roo...
9.8
rclone: Unauthorized File Access on Root System
ROOT-APP-GOBINARY-CVE-2026-41179
A vulnerability in rclone allows unauthorized access to files on a Root system. This is a significant risk because it could allow malicious users to access sensitive data. To protect your system, upda...
9.8
pyLoad Download Manager CAPTCHA Hack Allows Remote Code Execution
GHSA-8w3f-4r8f-pf53
CVE-2025-53890
PYSEC-2026-496
An attacker can execute code on your computer and gain access to your pyLoad account without needing a password. This can lead to stolen passwords, hijacked sessions, and complete control of your comp...
9.8
Node.js TLS Hostname Handling Can Cause Silent Authority Rebinding
CVE-2026-48930
BIT-node-2026-48930
A vulnerability in Node.js TLS (Transport Layer Security) hostname handling can allow attackers to secretly change the trusted server identity. This affects Node.js versions 22, 24, and 26. To protect...
9.8
Coolify prior to 4.0.0-beta.474 allows unauthorized server access
CVE-2026-57498
A security issue in Coolify's web interface allows users from one team to access and deploy servers managed by another team. This is fixed in version 4.0.0-beta.474. To stay secure, ensure you're runn...
9.6
Snowflake CLI versions before 3.19 allow malicious requests to internal networks
CVE-2026-13751
If you're using an older version of Snowflake CLI, a malicious SQL statement could trick your system into sending unauthorized requests to internal networks. To protect yourself, update to Snowflake C...
9.6
PraisonAI MCP Server Allows File System Access
CVE-2026-44336
GHSA-9mqq-jqxf-grvw
PYSEC-2026-472
A previous version of PraisonAI's MCP server allowed an attacker to write files outside of a specific directory, potentially leading to code execution. This issue has been fixed in version 4.6.34. To ...
9.9
OpenVPN Configuration in LuCI Allows Unauthorized Root Access
CVE-2026-58000
GHSA-pm9w-522m-8rrh
A security flaw in OpenVPN's LuCI configuration tool allows an authenticated user to gain root access to the system. This is a concern for systems with sensitive data, as an attacker could potentially...
9.4
Apache Tomcat: Missing Authorization Data in Logs
DEBIAN-CVE-2026-55276
A bug in Apache Tomcat's logging feature can cause certain security settings to be missed, potentially leading to unauthorized access to sensitive information. Affected users should upgrade to the lat...
9.1
Apache Tomcat: Missing Security Info in Logs
CVE-2026-55276
A security issue in older versions of Apache Tomcat may cause some security information to be missing from logs. This could make it harder to detect and respond to security threats. To fix this, updat...
9.1
Apache Tomcat: Invalid CRL configuration doesn't prevent FFM Connector issues
CVE-2026-53434
Apache Tomcat versions 11, 10, and 9 have a problem with certificate revocation lists (CRLs) that don't properly check for invalid certificates. This could allow malicious certificates to be used. To ...
9.1
iOS, iPadOS, macOS: Malicious App Crashes System
CVE-2026-39868
A security issue in iOS, iPadOS, and macOS allowed a malicious app to crash the system or damage its memory. This has been fixed in recent updates, but it's essential to install the latest versions to...
9.1
Alexantr Filemanager v.1.0 Remote Code Execution
CVE-2026-37637
The Alexantr Filemanager version 1.0 has a security issue that allows an attacker to run malicious code on a website. This could potentially allow an attacker to take control of the website or steal s...
9.1
Google MCP Toolbox HTTP Tool Can Make Unauthorized API Requests
CVE-2026-11720
The Google MCP Toolbox HTTP tool can make unauthorized API requests to unintended endpoints on the same target host. This is because an attacker can manipulate the URL to escape the intended path, pot...
9.3
pyload Download Manager: Malicious File Upload and Execution
GHSA-3f7w-p8vr-4v5f
CVE-2024-32880
PYSEC-2026-492
An authenticated user can upload a malicious file to the pyload download folder, potentially allowing an attacker to execute arbitrary code on the server. This is a serious security risk because it al...
9.1
Appsmith before 2.1 allows loopback access to services
CVE-2026-55455
BIT-appsmith-2026-55455
Appsmith, a platform for building internal tools and dashboards, had a security issue before version 2.1. This issue allowed an authenticated user to access internal services within the same container...
5.3
Red Hat Flatpak Security Update: Unauthorized File Access
RHSA-2026:30901
A security update has been released for Red Hat Flatpak to fix a vulnerability that could allow an attacker to access files they shouldn't have access to. This update is important for users who rely o...
9.0
Coolify: Authenticated Remote Code Execution via User Input
CVE-2026-34597
A security issue was found in Coolify's way of handling user input. This could allow an attacker with valid access to run malicious code on the server. Update to the latest version of Coolify to fix t...
8.8
Coolify: Authenticated Command Injection in Network Management
CVE-2026-34594
Coolify's network management feature had a security flaw that allowed authorized users to execute commands on managed servers as if they were the server administrator. This could be exploited to take ...
8.8