Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 9 July 2026

RSS

785 vulnerabilities published on 9 July 2026

Severity:
Langroid TableChatAgent: Unauthenticated Remote Code Execution
GHSA-q9p7-wqxg-mrhc CVE-2026-54769
Langroid's TableChatAgent is vulnerable to a critical security flaw that allows attackers to execute unauthorized code on the host system. This means an attacker could potentially take control of the ...
10.0
Ruflo: Unauthenticated attackers can access sensitive data
CVE-2026-59726
An older version of Ruflo's default setup allowed anyone on the network to access sensitive data without a password. This could let them read important keys and interfere with Ruflo's learning pattern...
10.0
SQLChatAgent in PostgreSQL can be bypassed by malicious queries
GHSA-6xc5-4r68-67fc CVE-2026-54760
A security flaw in PostgreSQL's SQLChatAgent allows hackers to bypass safety checks and execute malicious queries. This can lead to unauthorized access to sensitive data. To fix this issue, update you...
9.9
Neo4jChatAgent allows hackers to access or destroy database data
GHSA-2pq5-3q89-j7cc CVE-2026-55615
A vulnerability in Neo4jChatAgent allows hackers to read or delete all data in a Neo4j database, or even execute system commands on the server, by manipulating the input to the database. This can happ...
9.9
Palo Alto Networks PAN-OS: Large Scale VPN Data Corruption Risk
CVE-2026-0284
A vulnerability in Palo Alto Networks PAN-OS software affects its Large Scale VPN feature. This means an attacker with access to your network could potentially steal or alter sensitive data. To stay s...
4.7
Hermes WebUI < 0.51.788: Unauthenticated Remote Code Execution via Terminal API
CVE-2026-58123
A security flaw in older versions of Hermes WebUI allows attackers to run commands on the server without a password. This can happen if a hacker sends four specific requests to the server. To fix this...
9.3
YesWiki Bazar Calculator Allows Server Crash or Code Execution
CVE-2026-52778 GHSA-px5m-h76g-p7p8
YesWiki's Bazar calculator in older versions can cause the server to crash or allow attackers to execute malicious code. This is a serious issue because it could lead to a denial of service or unautho...
9.8
MERCURY MIPC252W RTSP Service Connection Disruption
CVE-2026-51599
An attacker can send a malicious request to the MERCURY MIPC252W's RTSP service, causing it to temporarily stop working for other users. This can happen without the attacker needing a password. To pro...
9.8
Xerte Online Tools allows attackers to run malicious code
CVE-2026-12116
The Xerte Online Tools have a security flaw that allows attackers to run their own code on the server. This can happen if the server settings are misconfigured, allowing an attacker to change the path...
9.8
rootio-varnish: Unpatched versions open to remote code execution
ROOT-OS-DEBIAN-11-CVE-2026-34475
A security patch has been released for the rootio-varnish package on Root:Debian:11. If you're using an unpatched version, an attacker could potentially execute malicious code on your system remotely....
9.8
Apache Tomcat Catalina Software Allows Unauthorized Access
ROOT-APP-MAVEN-CVE-2024-50379
A security patch has been released for Apache Tomcat Catalina software, which could allow attackers to access your system without permission. If you're using this software, you should update to a patc...
9.8
Apache Tomcat Core: Unpatched Servers Exposed to Remote Attacks
ROOT-APP-MAVEN-CVE-2026-43512
Apache Tomcat Core has a security patch available to prevent remote attacks. If not updated, servers using this component may be vulnerable to unauthorized access. Update to the latest patched version...
9.8
Apache Tomcat: Unauthorized Access to Sensitive Data
ROOT-APP-MAVEN-CVE-2025-31651
A vulnerability in the Apache Tomcat web server allows an attacker to access sensitive data without permission. This affects users who run Apache Tomcat, and it's essential to update the software to a...
9.8
BiEticaret SQL Injection via Malformed SQL
CVE-2026-5955
BiEticaret versions before 3.3.57 are vulnerable to a security risk that allows an attacker to manipulate data or access unauthorized information. This is a serious issue that can compromise the secur...
9.8
Blocksy Companion plugin for WordPress allows malicious file uploads
CVE-2026-15158
The Blocksy Companion plugin for WordPress has a security flaw that lets attackers upload files that could run malicious code. This is a concern because it could allow hackers to take control of a web...
9.8
Apache Tomcat Embedded Core: Privilege Escalation Risk
ROOT-APP-MAVEN-CVE-2026-41293
Apache Tomcat's embedded core library has been patched to prevent a security risk that could allow an attacker to gain elevated access. This affects users of the library in Root's Maven repository. Us...
9.8
miniOrange WordPress Plugin <= 5.5.1 - Administrator Account Takeover via OTP Bypass
CVE-2026-14245
A security flaw in the miniOrange WordPress plugin allows hackers to take control of administrator accounts by bypassing the one-time password (OTP) verification process. This can happen if the plugin...
9.8
gpsd GPS Device Subtype Command Injection Risk
DEBIAN-CVE-2026-58459
A security flaw in gpsd allows hackers to execute arbitrary commands on a system if they control the type of GPS device being used. This could lead to unauthorized access or data theft. To stay safe, ...
9.6
gpsd gpsprof Command Injection via gnuplot plot title
CVE-2026-58459
A security flaw in gpsd's gpsprof feature allows attackers to execute arbitrary commands on the system by manipulating the GPS device subtype value. This could potentially allow an attacker to take co...
8.4
PayRange 7.0.7 allows malicious JavaScript on Android devices
CVE-2026-13461
A security weakness in PayRange 7.0.7 for Android allows attackers to inject malicious code on users' devices, potentially leading to unauthorized actions. This issue is particularly concerning when c...
9.6
Apache Tomcat: Unauthenticated Access to Internal Server
ROOT-APP-MAVEN-CVE-2025-55754
Apache Tomcat's internal server is vulnerable to unauthorized access. This means an attacker could potentially access sensitive information or take control of your server. Update your Tomcat software ...
9.6
YesWiki PHP Object Injection via unserialize
GHSA-9369-69wj-7m2f CVE-2026-52777
YesWiki's Bazar feature is vulnerable to a PHP object injection attack when importing entries. An attacker can inject malicious code by posting a specially crafted request to the BazarImportAction. To...
9.4
XAPI Role-Based Access Control Allows Unauthorized Actions
CVE-2026-42486
A lower-privilege administrator in XAPI can perform unauthorized actions, such as reading and modifying files, marking a VM as a system domain, or affecting storage connections. This can lead to unint...
9.4
XenServer Role-Based Access Control Configuration Error
CVE-2026-23562
XenServer's role-based access control has multiple issues that allow administrators with lower privileges to access and modify sensitive system settings. This could lead to unauthorized changes to the...
9.4
XenServer Role-Based Access Control Settings Not Fully Restricted
CVE-2026-23561
XenServer's role-based access control settings are not fully restricted, allowing lower-privileged administrators to make changes they shouldn't be able to. This could allow an unauthorized user to ac...
9.4