Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 2 July 2026

RSS

1234 vulnerabilities published on 2 July 2026

Severity:
UniFi Connect Application Network Access Control Bypass
CVE-2026-50746
A vulnerability in UniFi Connect Application allows an attacker with network access to potentially take control of a device. This could happen if an attacker is able to execute malicious commands on t...
10.0
obs-service-tar_scm: Malicious Mercurial File Can Execute Code
CVE-2026-56004
The obs-service-tar_scm software has a vulnerability in its Mercurial handler. If an attacker can trick the service into checking out a malicious _service file, they can execute code as the service or...
10.0
Blocksy Companion Pro plugin <= 2.1.46 allows attackers to run malicious code.
CVE-2026-57624
The Blocksy Companion Pro plugin for WordPress has a security issue that allows hackers to run their own code on your website without needing a password. This means they could potentially delete or mo...
10.0
Azure OpenAI Privilege Escalation Over Network
CVE-2026-45499
Azure OpenAI's internal network access can be exploited by an authorized user, allowing them to access and manipulate sensitive data. This is a concern for organizations using Azure OpenAI, as it coul...
9.9
Microsoft Entra Provisioning Service allows attackers to gain extra access
CVE-2026-57100
An authorized attacker can use a Microsoft Entra Provisioning Service (SyncFabric) to gain extra access to a network. This is a concern because it allows an attacker to do things they shouldn't be abl...
9.9
Mautic 7: Malicious Files Can Be Written to Sensitive System Directories
CVE-2026-9559 GHSA-6r9h-4h75-7q4x
A security issue exists in Mautic 7's campaign import feature. An attacker with permission to import campaigns can write malicious files to sensitive areas of the system, potentially allowing them to ...
9.9
Mautic Theme Engine Allows Malicious Code Execution
CVE-2026-9558 GHSA-9fx4-7cmj-47vg
Mautic's theme engine is vulnerable to attacks that can execute malicious code on the hosting server. This is a risk because an authenticated user with permission to upload themes can potentially harm...
9.9
OpenClaw: Local User Can Forge Identity Headers
GHSA-rggc-m335-3wvj
A local user on the same network as an OpenClaw server could potentially trick the system into thinking they are a trusted user. This could allow them to access sensitive features or information. To f...
9.9
UniFi Protect Application SSRF Privilege Escalation Risk
CVE-2026-55115
The UniFi Protect Application is at risk of a security breach if a malicious actor can access the network. This could allow them to gain more control over the host device. To protect against this, ens...
9.9
UniFi Access Application: Malicious code execution via network access
CVE-2026-50748
A vulnerability in UniFi Access Application allows an attacker with low-level access to the network to potentially execute malicious code on the device. This could lead to unauthorized access or disru...
9.9
UniFi Talk App Privilege Escalation Risk
CVE-2026-50747
A hacker with network access and limited rights can use weaknesses in the UniFi Talk App to gain more control over the device. This could lead to sensitive data being accessed or modified. UniFi users...
9.9
ntopng versions 1 to 6.6 can be hijacked by session thieves
CVE-2026-38968
If you use ntopng to monitor network traffic, an attacker could potentially take control of your account by guessing your session ID. This is because ntopng generates session IDs in a way that's predi...
9.8
9router's Default Secret Allows Unauthenticated Access
GHSA-jphh-m39h-6gwx CVE-2026-49352
9router's default secret is hardcoded and publicly known, allowing unauthorized users to access the dashboard and API if the server's JWT secret is not set. This vulnerability affects many public 9rou...
9.8
GravitLauncher LaunchServer allows unauthorized access to files
GHSA-5g75-477j-2c2f CVE-2026-54617
A security flaw in GravitLauncher's LaunchServer allows any user to access and read any file on the server that the LaunchServer process can read. This could allow an attacker to access sensitive info...
9.8
9router: Unauthenticated Root Access and Data Execution
GHSA-g6g7-pvmx-m74p CVE-2026-59800
The 9router software does not properly check permissions for certain API requests, allowing an attacker to execute commands with root privileges and potentially take control of the system. This vulner...
9.2
AutoBangumi < 3.2.8: Default Credentials Can Be Used to Take Control
CVE-2026-58466
AutoBangumi versions before 3.2.8 contain a security flaw that allows attackers to use a known set of default login credentials to gain full access to the application. This is a concern because an att...
9.3
Redsea Cloud eHR allows unauthenticated attackers to upload malicious files
CVE-2024-14037
An attacker can upload malicious files to Redsea Cloud eHR without needing a login. This could allow them to take control of your system remotely. We recommend updating to the latest version of Redsea...
9.3
Yonyou KSOA 9.0: Unauthenticated File Upload Allows Remote Code Execution
CVE-2022-50973
An attacker can upload malicious files to a Yonyou KSOA 9.0 server without a password, potentially allowing them to execute code on the server. This is a serious risk because it allows unauthorized ac...
9.3
Dockwatch 0.6.567 Allows Unauthorized Access to Server
CVE-2026-58455
A security flaw in Dockwatch 0.6.567 allows an attacker to execute commands on your server without permission. This could lead to unauthorized access and potentially give the attacker control over you...
9.2
mcp-memory-service: Unauthenticated Access to Document API Endpoints
GHSA-84hp-mqvj-3p8h CVE-2026-50027
An attacker can upload, read, or delete sensitive data without a password. This is a security risk because it allows unauthorized access to user memories. To fix this, update the mcp-memory-service to...
9.8
Unauth Changes to UniFi OS Devices via Network Access
CVE-2026-55116
A security issue in UniFi OS devices allows unauthorized access to change settings. This could happen if an attacker is on the same network and has the right setup. To protect your devices, ensure you...
9.8
UniFi Protect Application Authentication Bypass Risk
CVE-2026-54408
The UniFi Protect Application has a security weakness that allows an unauthorized person with access to the network to bypass the authentication process for data streaming. This means they could poten...
9.8
Divi Form Builder plugin for WordPress allows hackers to upload malicious files
CVE-2026-5524
The Divi Form Builder plugin for WordPress allows hackers to upload malicious files to the website, which can be used to take control of the site. This is a serious security risk that affects all vers...
9.8
Booktics <= 1.0.21: Unauthenticated PHP Object Injection
CVE-2026-57621
Booktics software versions up to 1.0.21 are vulnerable to a type of attack that could allow an attacker to execute malicious code. This could lead to unauthorized access to sensitive data or system co...
9.8
WordPress ASE Pro <= 8.8.5 Cross Site Scripting Risk
CVE-2026-57625
An attacker can inject malicious code into WordPress sites using the ASE Pro plugin, potentially allowing them to steal sensitive information or take control of the site. This vulnerability affects al...
9.6