Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 30 June 2026

RSS

1576 vulnerabilities published on 30 June 2026

Severity:
Storage Concentrator (SC & SCVM) command injection risk via debug.pl script
CVE-2026-56415
An attacker can submit a malicious HTTP request to the Storage Concentrator's debug.pl script without a password, potentially allowing them to execute any system command with full access. This is a se...
10.0
Storage Concentrator (SC & SCVM) allows malicious commands via network packets
CVE-2026-56413
An attacker can send malicious data to Storage Concentrator (SC & SCVM) via the network, allowing them to execute any command on the system with full control. This is a significant risk because an att...
10.0
Google Chrome: Compromised browser can escape security sandbox
CVE-2026-13782
A critical security risk was found in older versions of Google Chrome. If an attacker had already taken control of your browser, they could have used a specially crafted webpage to break out of the se...
10.0
Google Chrome: Malicious Website Escapes Browser Security
DEBIAN-CVE-2026-13782
A critical security issue in older versions of Google Chrome allowed a hacker who had already compromised your browser to break out of the browser's security boundaries and potentially access your per...
10.0
IBM WebSphere Extreme Scale CORBA Stub Classes SSRF
CVE-2026-13773
IBM WebSphere Extreme Scale versions 8.6.1.0 through 8.6.1.6 have a security issue that allows an attacker to trick the system into making unauthorized connections to other servers. This could potenti...
10.0
IBM Langflow OSS Secrets Exposure and Data Manipulation
CVE-2026-10134
IBM Langflow OSS versions 1.0.0 through 1.9.3 have a security flaw that allows an attacker to access sensitive information and manipulate data within the system. This could lead to unauthorized access...
10.0
Adobe Campaign Classic: Unauthorized Code Execution Risk
CVE-2026-48286
Adobe Campaign Classic versions 7.4.3 and earlier have a security flaw that allows an attacker to execute code without permission. This could lead to unauthorized changes or data theft. Update to the ...
10.0
ColdFusion versions 2025.9 and earlier allow attackers to run code as you.
CVE-2026-48283
Certain versions of ColdFusion, a web development platform, have a security flaw that lets attackers upload malicious files and run code under your account. This could be exploited without your knowle...
10.0
ColdFusion versions 2025.9 and earlier allow malicious code execution.
CVE-2026-48281
If you use ColdFusion, an attacker could run unauthorized code on your system. This could happen without you even knowing it. To stay safe, update to a fixed version of ColdFusion as soon as possible.
10.0
ColdFusion: Unvalidated Input Can Execute Malicious Code
CVE-2026-48277
Versions 2025.9 and earlier of ColdFusion are vulnerable to a security flaw that could allow hackers to run malicious code on your server. This could lead to unauthorized access or data theft. To prot...
10.0
ColdFusion versions 2025.9 and earlier: Malicious file upload risk
CVE-2026-48276
ColdFusion versions 2025.9 and earlier are at risk of a security issue that allows hackers to upload malicious files, potentially allowing them to execute unauthorized code on the system. This issue c...
10.0
SeaweedFS allows attackers to access unauthorized data
CVE-2026-54917 CVE-2026-58372 GHSA-w62w-66v9-vvgv
SeaweedFS, a distributed storage system, has a security issue that allows attackers to access files from other buckets. This is fixed in version 4.30. Update to the latest version to protect your data...
8.6
IBM Langflow OSS: Authenticated Attackers Can Execute OS Commands
CVE-2026-7873
IBM Langflow OSS versions 1.0.0 through 1.10.0 have a security flaw that allows attackers who have already been authenticated to access sensitive information and take control of your system. This coul...
9.9
IBM Langflow OSS: Authenticated Attackers Can Execute Commands
CVE-2026-7873
IBM Langflow OSS versions 1.0.0 through 1.10.0 have a security flaw that lets anyone with a valid account run any system command and access sensitive information like passwords. This means an attacker...
9.9
Orkes Conductor Remote Code Execution via Malicious Workflow Definitions
CVE-2026-58138
A critical security issue in older versions of Orkes Conductor allows attackers to execute arbitrary system commands without authentication. This means that if an attacker can submit a malicious workf...
9.9
Fission: Unrestricted Access to Host Resources in Kubernetes
CVE-2026-50566 GHSA-m63v-2g9w-2w6v
Fission, a serverless framework for Kubernetes, had a security flaw that allowed a malicious user to gain control over a host's files and network. This could lead to a complete takeover of a node or e...
9.9
Fission Serverless Framework Exposes Sensitive Kubernetes Settings
CVE-2026-50564 GHSA-gx55-f84r-v3r7
A security issue in Fission's Environment CRD allowed unauthorized access to sensitive Kubernetes settings, such as network and user account information. This has been fixed in version 1.24.0. To stay...
9.9
Fission: Malicious Container Image Deployment via PodSpec Injection
CVE-2026-50563 GHSA-v455-mv2v-5g92
Fission, a Kubernetes-based serverless framework, had a security issue where a user could deploy malicious code. This was fixed in version 1.24.0. If you use Fission, update to the latest version to e...
9.9
Fission on Kubernetes allows malicious code to run
CVE-2026-50545 GHSA-wmgg-3p4h-48x7
Fission, a Kubernetes serverless framework, had a bug that allowed attackers to inject malicious code into functions and applications. This has been fixed in version 1.24.0. Users should update to thi...
9.9
Galera and MariaDB 11.8 Security Update for Linux
RHSA-2026:33412
A security update is available for Galera and MariaDB 11.8 on Linux systems. This update fixes potential security issues and improves the database's stability and performance. IT administrators should...
9.9
MariaDB 10.11 Security Update for Linux Systems
RHSA-2026:33093
MariaDB, a popular database management system, has released an update to fix security issues and other problems. This update is important for Linux systems that use MariaDB, as it helps protect agains...
9.9
Grav CMS before 2.0.0-beta.2 allows hackers to run malicious code
CVE-2026-56700
Grav CMS versions before 2.0.0-beta.2 are at risk of being hacked because of several security flaws. These flaws allow attackers to run malicious code on your website, steal sensitive information, or ...
9.3
Google Chrome on Linux: Malicious Traffic Can Execute Code
DEBIAN-CVE-2026-14121
A security issue in Google Chrome's Chromoting feature on Linux systems allowed a hacker to execute unauthorized code on a user's computer by sending malicious data over a network. This could potentia...
9.8
Google Chrome: Malicious HTML Code Execution
DEBIAN-CVE-2026-14104
A security issue in Google Chrome allowed hackers to run malicious code on a user's computer by tricking them into visiting a specially crafted website. This could lead to unauthorized access to sensi...
9.8
Google Chrome on ChromeOS: Untrusted Input Memory Read
CVE-2026-14090
A vulnerability in Google Chrome on ChromeOS allows a hacker to read data outside the allowed memory space by sending a specially crafted webpage. This could potentially allow the hacker to steal sens...
9.8