Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 8 July 2026

RSS

727 vulnerabilities published on 8 July 2026

Severity:
CoreWCF: Attackers can impersonate any user with admin privileges
GHSA-xjr9-gg9q-jx3v CVE-2026-54782
An attacker can use a known vulnerability in CoreWCF to pretend to be any user, including administrators, if they have access to the service and the trusted security token service's public certificate...
10.0
Nuclio: Persistent Remote Code Execution via Cron Triggers
GHSA-v5px-423j-pf7p CVE-2026-52831
Nuclio's cron trigger feature allows attackers to inject malicious commands into shell scripts, potentially leading to persistent remote code execution. This affects Nuclio versions up to 1.15.27. Use...
10.0
Plesk XML-RPC API: Low-Privileged Users Can Access Other Domains
CVE-2026-56843
A security issue in Plesk's XML-RPC API allows low-privileged users to see details of domains they don't own. This could lead to unauthorized access to sensitive information, such as FTP credentials, ...
9.9
Arbitrary Code Execution in Generic OEM UZ801 Router
CVE-2026-52200
A security issue in the Generic OEM UZ801_v2.1 4G LTE Router's web management API allows a remote attacker to potentially take control of the device. This could happen if the router is not properly se...
9.8
Mysterium Node Configuration Hijacking via Unauthenticated Access
CVE-2026-31309
An attacker can access and change Mysterium Node settings without a password, potentially taking control of the node. This is a serious issue because it allows an attacker to manipulate the node's beh...
9.8
MOVEit Transfer File Upload Bypass Vulnerability
CVE-2026-8801
MOVEit Transfer, a file transfer software, has a security weakness in its file upload module. This vulnerability can allow unauthorized access to the system, potentially leading to data theft or other...
9.8
Progress MOVEit Transfer Custom Reports Exposed to Unauthorized Data Access
CVE-2026-8649
Custom reports in Progress MOVEit Transfer can allow unauthorized users to access sensitive data. This affects MOVEit Transfer versions before 2026.0.0, 2025.1.3, and 2025.0.7. To fix this, update to ...
9.8
U-Boot NFS Client Buffer Overflow via Malicious NFS Server
CVE-2026-29009
A security flaw in U-Boot's NFS client allows a malicious NFS server to corrupt U-Boot's memory, potentially taking control of the system. This vulnerability affects U-Boot versions up to 2026.04-rc3 ...
8.8
IBM API Connect Password Reset SQL Injection
CVE-2026-9074
IBM API Connect versions 10.0.8.0 to 10.0.8.9 and 12.1.0.0 to 12.1.0.3 have a security weakness in the password reset feature. An attacker can access sensitive data without needing a password. To stay...
9.8
IBM API Connect Uses Default Credentials
CVE-2026-3144
IBM API Connect 12.1.0.0 to 12.1.0.3 uses default passwords. This can allow unauthorized access to the application. To fix this, update the credentials to strong, unique passwords.
9.8
Blocksy Companion Pro < 2.1.47 allows attackers to upload malicious files
CVE-2026-58480
The Blocksy Companion Pro plugin for WordPress is affected if it's version is less than 2.1.47. Attackers can upload malicious files, such as executable code, which can lead to unauthorized access and...
9.2
Mediküm Web: Unsecured SQL Commands Allow Unauthorized Access
CVE-2026-8307
Mediküm Web, a software used by Webbeyaz Web Design, has a security flaw that allows hackers to manipulate database commands. This could allow unauthorized access to sensitive information. Since the s...
9.8
Perl Imager versions before 1.033 crash from malformed images
DEBIAN-CVE-2026-14454
Perl Imager versions before 1.033 can crash when processing certain image files. This is a security concern because an attacker could create a malicious image that crashes a worker process. Update to ...
9.8
Imager for Perl: Large Image Can Crash the Program
CVE-2026-14454
Imager versions before 1.033 for Perl can crash if it processes a large image. This could be exploited by an attacker to intentionally shut down the program. To stay safe, update to Imager version 1.0...
9.8
Imager for Perl versions before 1.033: Malicious Image Crash
UBUNTU-CVE-2026-14454
Imager, a Perl image processing library, has a bug that can cause a program to crash when it processes a malicious image. This can happen if the program is processing images from an untrusted source. ...
9.8
DELIMIA Apriso Server Privilege Access Risk from 2020 to 2026
CVE-2026-9695
The DELMIA Apriso software has a security weakness that allows unauthorized access to its server. This means an attacker could potentially gain control over the server, which could lead to data theft ...
9.8
WP Learn Manager <= 1.1.8 - Unauthenticated Plugin Installation and Activation
CVE-2026-12153
The WP Learn Manager plugin for WordPress has a security flaw that allows anyone to install and activate plugins without permission. This could lead to malicious plugins being added to your site, pote...
9.8
WordPress Eventer Plugin <= 4.4.2 - Unauthenticated User Account Takeover
CVE-2026-9701
The Eventer plugin for WordPress stores password reset keys in plain text, making it possible for attackers to reset any user's password without needing a password. This is especially concerning becau...
9.8
Google Chrome Android Autofill Sandbox Escape
CVE-2026-15113
A remote attacker could potentially escape Google Chrome's security sandbox on Android devices, allowing them to access sensitive data and potentially take control of the device. This affects all Andr...
9.6
Google Chrome Android Autofill Data Exposure
DEBIAN-CVE-2026-15113
A security flaw in Google Chrome's Autofill feature on Android devices allowed hackers to potentially access sensitive information and escape the browser's security protections. This issue was present...
9.6
Joro: Unauthenticated Plugin Upload Allows Remote Code Execution
GHSA-xqhv-chqm-fhcc CVE-2026-53649
Joro's default proxy mode allows attackers to upload malicious plugins and execute code on the system without a password. This can happen when a user visits a website with malicious JavaScript. To fix...
9.6
Snowflake Snowpark Python SDK allows unauthorized database access
CVE-2026-15062
Authenticated users with low privileges in Snowflake can execute unauthorized SQL commands using the Snowpark Python SDK. This could allow them to access or steal sensitive data. To protect your data,...
9.6
JupyterLab Git Extension: Malicious File Names Can Execute Code
GHSA-f962-v9hr-pfg5 CVE-2026-54527
The JupyterLab Git extension allows attackers to create malicious file names that can execute code when viewed by others. This can lead to unauthorized access to sensitive information or credentials. ...
9.4
Horde VFS API before 3.0.1: Malicious File Uploads Can Execute Commands
DEBIAN-CVE-2026-60102
The Horde Virtual File System API, used by some applications, has a security flaw that allows attackers to execute system commands by uploading malicious files. This means that an attacker could poten...
9.4
OpenSSH Server Key Change Causes Client Crash
CVE-2026-60002
OpenSSH servers before version 10.4 can crash connected clients if their host key is changed during a secure connection. This could potentially be exploited by an attacker, but only if they have alrea...
9.4