Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 7 July 2026

RSS

664 vulnerabilities published on 7 July 2026

Severity:
ColdFusion: Path Traversal Vulnerability Can Execute Malicious Code
CVE-2026-48282
ColdFusion versions 2025.9 and earlier are at risk of allowing attackers to execute malicious code on a server without needing user interaction. This means that an attacker could potentially take cont...
10.0 KEV
Incus allows malicious images to read and write host files
GHSA-vxp5-584q-c479 CVE-2026-48752 GO-2026-5803
Incus, a container management software, can be tricked into allowing malicious images to read and write files on the host system. This could potentially allow an attacker to execute malicious code on ...
9.9
Incus allows arbitrary file writes via crafted images
GHSA-73hr-m85f-64v9 CVE-2026-48750 GO-2026-5801
A vulnerability in Incus allows attackers to write files to arbitrary locations on the host system by creating a specially crafted image. This can potentially lead to unauthorized command execution. T...
9.9
Incus S3 Multipart Upload allows arbitrary file creation
GHSA-ccjc-4qc3-jxqc CVE-2026-48753 GO-2026-5802
A vulnerability in Incus's S3 protocol upload endpoint allows attackers to create arbitrary files on the host, potentially leading to unauthorized command execution. This affects Incus users who rely ...
9.9
Incus allows malicious images to access host files
GHSA-2q3f-q5pq-g8wv CVE-2026-48749 GO-2026-5798
A malicious image can read and write any file on the host, potentially allowing an attacker to execute any command. This is a serious security risk, and users should be cautious when importing images ...
9.9
Incus allows attackers to write arbitrary files on the host
GHSA-v6mj-8pf4-hhw4 CVE-2026-48755 GO-2026-5808
A vulnerability in Incus's backup compression feature allows attackers to write arbitrary files on the host, potentially leading to unauthorized access. This issue affects Incus's backup compression f...
9.9
Incus allows malicious snapshots to bypass project restrictions
GHSA-48q5-w887-33wv CVE-2026-48751 GO-2026-5799
Incus has a security issue that allows a malicious user to bypass project restrictions and execute arbitrary commands on the server with root privileges. This is a serious problem because it could all...
9.9
Incus client writes files to arbitrary locations
GHSA-f6m5-xw2g-xc4x CVE-2026-48769 GO-2026-5806
A malicious image server can write files to any location on the Incus server, potentially allowing an attacker to execute commands as root. This is due to a weakness in how Incus handles image downloa...
9.9
Coolify: Low-Privileged Users Can Run Server Commands
CVE-2026-34048
A security issue in Coolify's terminal feature allows team members with limited access to run server commands on other team members' servers. This could lead to unintended changes or data loss. To fix...
9.9
Coolify: Cloning resources into other teams' accounts
CVE-2026-34037
A previous version of Coolify allowed authorized users to copy resources into accounts they shouldn't have access to. This means they could potentially access or modify sensitive information. Update t...
9.9
Coolify: Unauthorized Access to Server Management Tools
CVE-2026-34047
Coolify, a server management tool, had a security flaw that allowed authorized users to access and execute commands on parts of the system they shouldn't have. This was fixed in version 4.0.0-beta.471...
9.9
Fire-Boltt Smartwatch Firmware: Unauthenticated Access to Device Functions
CVE-2026-37271
Fire-Boltt smartwatches with certain firmware versions may allow unauthorized access to their functions. This means that someone with the right tools and information could potentially control or acces...
9.8
Trueview Security Camera Password Bypass Risk
CVE-2026-37270
The Trueview Security Camera's password validation is faulty, allowing unauthorized access. This is particularly concerning because the camera's firmware contains hardcoded administrator credentials, ...
9.8
Perl DBI versions before 1.650 can crash with SQL errors
DEBIAN-CVE-2026-14739
Old versions of the Perl DBI library can crash if a SQL query has too many placeholders, potentially causing system instability. This is a significant issue because it can happen unexpectedly and disr...
9.8
Perl DBI versions before 1.650 allow SQL data overflow
CVE-2026-14739
Perl's DBI database interface is vulnerable to a data overflow when handling SQL statements with a very large number of placeholders. This could potentially allow an attacker to crash the system or ex...
9.8
mem0 OpenMemory API Unauthenticated Access Risk
CVE-2026-59705
The mem0 OpenMemory API allows unauthenticated access to user memories, which could lead to private data exposure or denial-of-service. This vulnerability affects the openmemory/api component of mem0....
9.3
Perl DBI versions before 1.650 can crash from SQL preparsing
CVE-2026-14739
Old versions of Perl's DBI module can crash when preparing SQL statements with an extremely large number of placeholders. This is a security risk because it can allow an attacker to cause the system t...
9.8
9router: Unauthenticated Root Access and Code Injection
CVE-2026-59800 GHSA-g6g7-pvmx-m74p
An attacker can execute arbitrary code with root privileges on your system. This can happen if you're using the 9router package and it's running as root. To fix this, update to the latest version of 9...
9.2
9router: Unauthenticated Root Access and Data Execution
GHSA-g6g7-pvmx-m74p CVE-2026-59800
The 9router software does not properly check permissions for certain API requests, allowing an attacker to execute commands with root privileges and potentially take control of the system. This vulner...
9.9
Portal for ArcGIS Weak Password Recovery Exposes User Accounts
CVE-2026-13020
A security weakness in Portal for ArcGIS versions 12.1 and earlier allows an unauthorized attacker to take control of a user's account. This affects Windows, Linux, and Kubernetes systems. To protect ...
9.8
Unauthenticated Access to Esri Portal for ArcGIS API
CVE-2026-13019
Esri Portal for ArcGIS versions 12.1 and earlier have a security issue that allows attackers to access certain parts of the system without a password. This is a concern for organizations that use this...
9.8
Dell PowerProtect Data Domain: Unauthenticated Access Risk
CVE-2026-53483
Dell PowerProtect Data Domain software versions 7.7.1.0 through 8.7 have a security flaw that allows an unauthorized attacker to access the system remotely. This poses a significant risk, as an attack...
9.8
Dell PowerProtect Data Domain, Path Traversal Risk, Unauthorized Access
CVE-2026-53481
Dell PowerProtect Data Domain, a data management system, contains a vulnerability that allows an unauthorized attacker to gain full access to the system. This could lead to sensitive data being compro...
9.8
Debian OpenSSL Certificate Validation Weakness in Apache
DEBIAN-CVE-2011-10043
A weakness in Debian's OpenSSL certificate validation affects Apache servers. This means that an attacker could potentially create a fake certificate that would be accepted as legitimate by a Debian-b...
9.8
Perl Module::Load versions before 0.22 allow arbitrary module loading
CVE-2011-10043
Old versions of Perl's Module::Load module can load unauthorized modules, allowing attackers to execute malicious code. This affects Perl applications that use Module::Load. To fix this, update to Mod...
9.8