Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 6 July 2026

RSS

829 vulnerabilities published on 6 July 2026

Severity:
9Router API Keys and Data Exposed Without Password
GHSA-vjc7-jrh9-9j86
A critical security issue in 9Router's API allows anyone to access sensitive data, including API keys and user conversations. This means that unauthorized users can view and potentially misuse your AP...
10.0
9Router API Keys Leaked and Unsecured Data Access
GHSA-vjc7-jrh9-9j86
An outdated version of 9Router's API is vulnerable to unauthorized access to sensitive data, including API keys and user conversations. This could allow attackers to steal sensitive information and co...
10.0
Crawl4AI Web Crawler Allows Unauthorized Command Execution
CVE-2026-57572
The Crawl4AI web crawler, used for scraping and crawling, had a security issue prior to version 0.9.0. An attacker could exploit this issue to run malicious code on the system, potentially leading to ...
10.0
Traefik: attackers can spoof identity headers
CVE-2026-54763
Traefik, a web server helper, had a security weakness that allowed hackers to fake identity information. This could happen if a hacker reached a protected part of a website. The good news is that this...
7.8
ColdFusion: Unvalidated User Input Can Execute Code
CVE-2026-48316
ColdFusion versions 2025.9 and earlier are affected by a security issue that could allow an attacker to execute code with the privileges of the current user. This means an attacker could potentially a...
10.0
Coolify Server Management Tool: Unauthorized Remote Access
CVE-2026-34038
Coolify, a server management tool, had a security flaw that allowed users with permission to manage applications to access the server remotely and steal sensitive information. This issue has been fixe...
9.9
Plesk XML API: Malicious User Can Write Root Files
CVE-2026-48614
An attacker with a Plesk account can write files with root access, potentially leading to server compromise. This is a serious issue, as it allows unauthorized access to sensitive server settings. To ...
9.9
BeyondTrust Remote Support: Unauthorized Data Access
CVE-2026-40141
A security weakness in BeyondTrust Remote Support and Privileged Remote Access could allow authorized users to access data they shouldn't see. This is a concern because it could compromise sensitive i...
8.5
Apache HTTP Server contains hidden admin login backdoor
CVE-2026-11405
The Apache HTTP Server has a hidden login backdoor that allows anyone to gain admin access by entering the correct password. This backdoor is not protected by a username, so any username can be used. ...
9.8
ArcGIS Server allows attackers to upload malicious files
CVE-2026-9182
ArcGIS Server has a security weakness that lets attackers upload files without permission. This could allow them to do harm to your system. To protect yourself, make sure you keep ArcGIS Server up to ...
9.8
BeyondTrust Remote Support allows unauthorized access
CVE-2026-40139
An attacker can bypass security checks and gain access to BeyondTrust Remote Support, including accounts with high-level permissions, if a specific configuration is set up. This could lead to unauthor...
9.2
Formie Hidden field defaults vulnerable to server-side code execution
GHSA-565m-g33j-jq96 CVE-2026-52889
An unauthenticated attacker can execute server-side code by visiting a public form with a hidden field that uses a dynamic default value. This could lead to sensitive information disclosure, applicati...
9.8
Apache Camel AWS SNS: Unsecured Input Headers Removed
CVE-2026-56140
The Apache Camel AWS SNS component has fixed a security weakness that allowed malicious data to be injected into its system. This was not possible in this specific component because it does not receiv...
9.8
Apache Camel Keycloak: Unverified Access Tokens in Default Configuration
CVE-2026-53913
In the default configuration of Apache Camel Keycloak, access tokens are not verified, allowing any non-null value in the Authorization: Bearer header to pass. This means that even an invalid or forge...
9.8
Apache Camel: Unauthenticated Access to MongoDB Data
CVE-2026-48204
Apache Camel's MongoDB component allows unauthenticated HTTP clients to switch MongoDB operations, including deleting files, without a password. This means that anyone can access and delete files stor...
9.8
Apache Camel: Malicious headers can be injected in SQS messages
CVE-2026-46456
Apache Camel's SQS component allows malicious users to inject custom headers into messages. This could be exploited by attackers to manipulate the behavior of downstream systems, potentially leading t...
9.8
Apache Camel Keycloak: Accepts Expired Access Tokens
CVE-2026-46455
Apache Camel's Keycloak component fails to verify access token expiration dates, allowing expired tokens to be accepted. This issue affects Apache Camel versions 4.18.0 to 4.18.3 and 4.19.0 to 4.21.0....
9.8
Apache Camel: Unauthenticated Clients Can Inject Control Headers
CVE-2026-46454
Apache Camel's CometD component doesn't check incoming messages for security. This allows unauthenticated clients to inject custom headers that can affect how the system behaves, potentially causing i...
9.8
Apache Camel: Untrusted Data Deserialized in Key Manager
CVE-2026-43867
Apache Camel's key manager can execute malicious code when it reads key metadata from AWS Secrets Manager. This happens if an attacker has write access to the AWS Secrets Manager secret that holds the...
9.8
Apache IoTDB: Untrusted Network File Write Risk
CVE-2026-24014
Apache IoTDB allows an attacker to write files on the system if the internal RPC port is exposed to an untrusted network. This could lead to unauthorized data changes or system compromise. To fix this...
9.8
PROG MIS ERP App Uses Hard-coded Login Credentials
CVE-2026-14807
The PROG MIS ERP App stores its login credentials directly in the code, which can be accessed by unauthorized users. This allows them to log in to the app and potentially view sensitive data. To prote...
9.3
Prog Management System - Exposure of Database Credentials
CVE-2026-14808
The Prog Management System allows unauthorized access to sensitive database information, including login credentials. This puts the system and its data at risk of unauthorized access and potential mis...
9.3
Crawl4AI: Uncontrolled File Writes from Malicious Input
CVE-2026-57571
The Crawl4AI web crawler and scraper saves downloaded files using user-controlled names, potentially allowing attackers to write files anywhere on the system. This could lead to remote code execution ...
9.6
Adobe Commerce allows access to other companies' data
CVE-2026-12686
Adobe Commerce does not properly check user access to company data, which means an authenticated user could see or change sensitive information from other companies hosted on the same website. This co...
9.3
FOSSBilling Payment Bypass via Fake Payment Request
CVE-2026-42341
FOSSBilling's payment system has a weakness that allows an attacker to trick the system into paying invoices without actually paying. This can happen if the Custom payment adapter is enabled and an at...
9.2