Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 3 July 2026

RSS

522 vulnerabilities published on 3 July 2026

Severity:
Gardyn IoT Hub Exposes Sensitive Device Credentials
CVE-2026-13768
Gardyn IoT devices have a security flaw that allows hackers to access sensitive information about all connected devices and potentially take control of them. This could lead to unauthorized access to ...
9.5
Gitea pre-receive hook can miss branch-protection checks
CVE-2026-27780
Gitea versions before 1.26.0 have a security issue that can allow someone to push changes to a protected branch if the Gitea server receives very large input. This is a concern because it can allow un...
9.8
Gitea LFS Push Allows Bypassing Configured Security
CVE-2026-26292
Versions of Gitea before 1.25.5 allow attackers to bypass security restrictions for large file transfers. This can allow unauthorized access to sensitive data. To fix this, update to Gitea version 1.2...
9.8
Keras 3.14.0 Arbitrary Code Execution Risk
DEBIAN-CVE-2026-12481
A security issue in Keras 3.14.0 allows an attacker to execute malicious code on the server or user's machine. This could happen if an attacker is able to manipulate the data used to load or clone Ker...
9.8
Root:npm protobufjs Data Tampering Risk
ROOT-APP-NPM-CVE-2026-41242
The @rootio/protobufjs package in Root:npm has a data tampering risk. This means that an attacker could manipulate data to deceive users. Root has released a patch to fix this issue, and you should up...
9.8
Root vitest: Unauthenticated Code Execution Risk
ROOT-APP-NPM-CVE-2026-47429
The Root vitest package had a vulnerability that could allow an attacker to execute unauthorized code. This could have let a malicious user access or modify sensitive data. Root has released a patch t...
9.8
rootio-openexr: Malicious Image Can Crash Server
ROOT-OS-DEBIAN-11-CVE-2026-42217
The rootio-openexr software, used for image processing, has a bug that can be exploited by a malicious image file. This could cause a server to crash, leading to downtime and potential data loss. Root...
9.8
Raera Destekz SQL Injection Risk: Unsecured User Input
CVE-2026-4321
A security weakness in Raera Destekz's software allows hackers to inject malicious SQL code, potentially accessing or modifying sensitive data. This issue affects Destekz's users and can be exploited ...
9.8
Apache Lucene.Net: Malicious XML Data Can Cause Harm
CVE-2026-47898
Apache Lucene.Net's PatternParser has a weakness that can allow attackers to inject malicious XML data. This could potentially cause harm to your system. To fix this, update to version 4.8.0-beta00018...
4.0
Hplip: Incomplete Fix Allows Privilege Escalation
CVE-2026-14544
A fix for a previous Hplip vulnerability was not fully implemented, leaving the software open to potential attacks. This could allow a malicious attacker to gain higher-level access to a system. Users...
9.8
libcurl Leaks Old Proxy Passwords
CURL-CVE-2026-9079 CVE-2026-9079
libcurl, a software used for internet transfers, has a flaw that can expose old proxy passwords. This is a concern because it allows unauthorized access to proxy servers. To protect your systems, upda...
9.8
libcurl Passes Wrong Passwords Between Websites
CURL-CVE-2026-11856 CVE-2026-11856
A bug in libcurl can cause it to accidentally send passwords meant for one website to another. This can happen if you use libcurl to log in to a website with a password, and then try to access another...
9.8
libcurl HTTP/2 stream dependency tree access error
DEBIAN-CVE-2026-10536
Libcurl, a widely-used library for making HTTP requests, has a bug that could allow an attacker to cause a crash or potentially exploit the system if a web application uses libcurl to handle HTTP/2 co...
9.8
libcurl HTTP/2 Stream Dependency Data Leak
CURL-CVE-2026-10536 CVE-2026-10536
A security issue exists in libcurl's HTTP/2 feature when resetting a connection. If an application uses this feature and then closes the connection, sensitive data may be leaked. To fix this, update t...
9.8
HPLIP Print Data Can Allow Remote Privilege Escalation
UBUNTU-CVE-2026-14544
HPLIP, a software used for printing with HP devices on Linux systems, has a security issue. If an attacker sends specially crafted print data, they could potentially gain more access to the system or ...
9.8
WatchGuard Firebox: Unauthenticated Code Execution via IKEv2 LDAP Auth
CVE-2026-13368
A vulnerability in WatchGuard Firebox's Mobile User VPN with IKEv2 allows an attacker to run unauthorized code on affected devices. This affects WatchGuard Firebox devices using IKEv2 with an external...
9.2
Gitea OAuth Token Exchange Without Verification
CVE-2026-26247
Gitea versions before 1.25.5 have a security issue that could allow unauthorized access to tokens. This is a concern because it could lead to attackers getting access to sensitive information. To fix ...
9.1
Gitea OAuth2 Codes Not Expired or Reused
CVE-2026-26232
Gitea versions before 1.25.5 may allow unauthorized access if an attacker intercepts an OAuth2 authorization code. This is because Gitea does not enforce a time limit for the code to be used and does ...
9.1
Gitea template generation can access unintended files
CVE-2026-25718
Gitea versions before 1.25.5 can read or write files outside intended templates, potentially exposing sensitive data. This affects users who store templates in non-standard locations. To protect your ...
9.1
Gitea Repository Creation Field Validation Missing
CVE-2026-22547
Gitea versions before 1.25.5 allow users to create repositories with invalid settings. This can lead to security issues or data corruption. To fix this, update Gitea to version 1.25.5 or later.
9.1
Gitea: Private repositories exposed through archive download
GHSA-cr4g-f395-h25h CVE-2026-20706
A vulnerability in Gitea allows users with personal access tokens of any scope to download private repository archives. This affects users who have created such tokens, potentially exposing sensitive ...
5.3
Perl's Net::IP::LPM versions through 1.10 allow data to be read past its limits
CVE-2026-56015
A bug in the Net::IP::LPM module for Perl could allow an attacker to access memory they shouldn't. This bug is not likely to cause direct harm but could be detected by certain security tools. To stay ...
9.1
rootio-openexr: Unsecured File Access in Root Environment
ROOT-OS-DEBIAN-11-CVE-2026-42216
The rootio-openexr package in Root's Debian 11 environment had a security issue that could allow unauthorized access to sensitive files. Root has released a patch to fix this issue, and users are advi...
9.1
libcurl Leaks Proxy Authentication Info Between Transfers
CURL-CVE-2026-8927 CVE-2026-8927
When using libcurl to transfer data through multiple proxies, sensitive authentication information may be accidentally shared between transfers. This can happen when the proxy settings are changed bet...
9.1
curl Exposes Passwords with .netrc and Username in URL
CURL-CVE-2026-8926 CVE-2026-8926
Curl incorrectly retrieves passwords from .netrc files when a username is specified in the URL. This can expose passwords for the wrong user if multiple users are configured for the same host. To prev...
9.1