Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 1 July 2026

RSS

1108 vulnerabilities published on 1 July 2026

Severity:
Rancher Fleet: Unvalidated Secret Access in Multi-Tenant Environments
GHSA-xr65-5cpm-g36x CVE-2026-44935
Fleet, a tool used in Rancher Manager, has a security flaw that allows unauthorized access to sensitive data in multi-tenant environments. This means that one tenant could access and read the secrets ...
9.9
Debian Linux: Unauthenticated Remote Code Execution
DEBIAN-CVE-2026-50195
An attacker can run malicious code on Debian Linux systems without needing a password. This affects all Debian Linux versions before a specific update. To protect your system, apply the latest securit...
7.3
MariaDB 11.8 Security Update for Linux Systems
RHSA-2026:33481
A security update is available for MariaDB 11.8 on Linux systems. This update fixes several security issues, bugs, and enhances the database management system. To ensure your system remains secure, ap...
9.9
MariaDB 10.11 Security Update for Linux
RHSA-2026:33482
MariaDB, a popular database management system, has released a security update to fix potential security risks. These risks could allow unauthorized access to sensitive data. To protect your system, it...
9.9
MySQL Database Security Update for Red Hat
RHSA-2026:33464
A security update is available for the MySQL database on Red Hat systems. This update addresses several security issues, including potential data exposure and unauthorized access. Users should apply t...
9.9
UTT nv518G Software Arbitrary Code Execution
CVE-2026-52186
A security issue in UTT nv518G software allows an attacker to run unauthorized code on the system. This can happen if an attacker sends malicious input to the software, potentially leading to system c...
9.8
Shenzhen Aitemi M300 Wi-Fi Repeater allows network access to execute commands
CVE-2026-58457
The Shenzhen Aitemi M300 Wi-Fi Repeater has a security flaw that lets hackers with access to the same network take control of the device. This is because the device doesn't check the input it receives...
9.3
SQL Injection in Wikimedia Mediawiki Cargo Extension
CVE-2026-14363
The Wikimedia Mediawiki Cargo Extension is vulnerable to SQL injection attacks, which could allow unauthorized access to sensitive data. This affects versions of the extension prior to 1.43.9, 1.44.6,...
6.9
SQL Injection in Mediawiki Cargo Extension
CVE-2026-58521
A flaw in the Mediawiki Cargo Extension could allow hackers to inject malicious SQL code, potentially leading to unauthorized access to sensitive data. This affects users of the Cargo Extension in Med...
6.9
JAIOTlink C492A-W6 IP cameras have hardcoded admin credentials
CVE-2026-58453
Some JAIOTlink C492A-W6 IP cameras have a security flaw that lets nearby hackers access the camera using a default username and an empty password. This can allow hackers to view camera footage, change...
9.3
Guardian Language-System Executes Arbitrary OS Commands
CVE-2026-34117
The Guardian language-system allows an unauthenticated attacker to execute arbitrary operating system commands on the server. This could lead to unauthorized access, data theft, or server compromise. ...
9.3
Guardian Language System Unauthenticated Command Execution
CVE-2026-34116
The Guardian language system has a security flaw that allows an attacker to execute arbitrary commands on the server without needing a password. This can happen if an attacker sends a specially crafte...
9.3
Guardian Language-System Amazon Transcription Exposes Server to Command Injection
CVE-2026-34115
An attacker without a login can execute arbitrary OS commands on the Guardian language-system server by manipulating the Amazon transcription request. This is a security risk because it allows unautho...
9.3
Guardian language-system allows arbitrary OS command execution
CVE-2026-34114
The Guardian language-system has a security issue that allows an attacker to execute commands on the server without needing a login. This is a serious problem because it can allow the attacker to acce...
9.3
Guardian language-system allows unauthenticated OS command execution
CVE-2026-34113
The Guardian language-system has a security issue that allows an attacker to execute arbitrary operating system commands on the server without needing to log in. This could be used to access or modify...
9.3
Guardian Language System Allows Unauthenticated Command Execution
CVE-2026-34112
An attacker can access your Guardian language system without a password and run unauthorized commands on your server. This can allow the attacker to view, edit, or delete sensitive files. To fix this,...
9.3
Guardian Language-System Allows Unauthenticated OS Command Execution
CVE-2026-34111
An attacker can run arbitrary system commands on the Guardian server without a password, potentially gaining access to sensitive data or disrupting the system. This is a serious risk because no authen...
9.3
Guardian Language-System PHP Exec Command Injection
CVE-2026-34110
The Guardian language-system does not properly check user input, allowing an attacker to execute arbitrary system commands on the server. This can happen if an attacker sends a specially crafted reque...
9.3
Guardian Language-System Allows Remote Code Execution
CVE-2026-34109
The Guardian language-system has a security flaw that allows an attacker to execute any command on the server without needing a password. This could allow the attacker to access sensitive data or take...
9.3
Guardian: Unauthenticated Remote Command Execution via GET Parameter
CVE-2026-34108
An unauthenticated attacker can execute arbitrary system commands on the Guardian server by appending malicious characters to the GET 'id' parameter. This can lead to unauthorized access and data mani...
9.3
PACSgear MediaWriter 5.2.1 allows unauthenticated file access and code execution
CVE-2026-58127
PACSgear MediaWriter 5.2.1 has a security flaw that allows an attacker to access and modify files on the computer without a password. This can lead to the attacker being able to run malicious code on ...
9.3
PACSgear PACS Scan 5.2.1 allows unauthorized file access and code execution
CVE-2026-58126
A security flaw in PACSgear PACS Scan 5.2.1 allows hackers to access and modify any file on the system without a password, potentially giving them control over the system. This is a serious issue beca...
9.3
Guardian language-system: Unauthenticated OS command execution
CVE-2026-34107
The Guardian language-system has a security flaw that allows an attacker to execute arbitrary commands on the server without needing a password. This can be exploited by a malicious user who visits th...
9.3
MediaWiki allows unauthorized data to be executed.
CVE-2026-58025
MediaWiki, a popular wiki software, has a security issue that could allow attackers to execute unauthorized code. This affects older versions of MediaWiki, so it's essential to update to the latest ve...
5.9
Control Web Panel before 0.9.8.1225 allows remote code execution
CVE-2026-57517
An attacker can inject malicious code into Control Web Panel, allowing them to execute arbitrary commands on the server. This can happen if you're running an outdated version of the software. To prote...
9.3