Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 10 July 2026

RSS

903 vulnerabilities published on 10 July 2026

Severity:
RabbitMQ: Guest User Can Connect Remotely Through Proxy
CVE-2026-57216
A security issue in older RabbitMQ versions allowed a guest user to connect from outside the local network through a proxy. This could be a risk if your RabbitMQ server is exposed to the internet. To ...
10.0
RabbitMQ allows unauthorized remote access to some users
DEBIAN-CVE-2026-57216
Old versions of RabbitMQ allowed a certain type of user to connect to the system from outside the network when certain conditions were met. This is a security risk because it could allow unauthorized ...
10.0
RabbitMQ on Windows exposes users to malicious UNC paths
CVE-2026-57211
A bug in the RabbitMQ management plugin on Windows versions prior to 4.1.11 and 4.2.6 can allow an attacker to trick the system into accessing malicious shared files. This could lead to unauthorized a...
10.0
RabbitMQ allows guest user to connect from outside
UBUNTU-CVE-2026-57216
RabbitMQ, a messaging service, had a security weakness in older versions. This weakness could allow a user with limited access to connect to the service from outside the local network. To fix this, up...
10.0
OpenPLC v3: Malicious Files Can Be Uploaded and Executed
CVE-2026-14480
An attacker with a valid login can upload a malicious file to OpenPLC v3, potentially allowing them to execute arbitrary code on the system. This can happen if the attacker uploads a malicious file to...
8.7
SiYuan Personal Knowledge Management System: Stored XSS Vulnerability
CVE-2026-50551 GHSA-56mp-4f3v-fgj2
SiYuan, a personal knowledge management system, contains a security flaw that can allow an attacker to execute malicious code on users' computers. This vulnerability affects users who use the Electron...
9.9
SiYuan 3.7.0: Unsecured Data in Personal Knowledge Management System
CVE-2026-54158 GHSA-5xfx-xj4h-5p7r
An attacker with write access to a synced workspace can inject malicious code into SiYuan, potentially allowing them to execute commands on a user's computer. This vulnerability has been fixed in vers...
9.9
SiYuan prior to 3.7.0: Untrusted CSS can run malicious JavaScript
CVE-2026-54067 GHSA-mvjr-vv3c-w4qv
An attacker with access to your SiYuan workspace can inject malicious code that runs on all devices syncing the workspace. This happens even if you've disabled running untrusted JavaScript. To fix thi...
9.9
9routers Exposes Sensitive Data and Database
GHSA-qvfm-67h2-2qfx CVE-2026-55500
The 9routers software exposes sensitive data and allows unauthorized access to its database. This can lead to complete credential theft and database takeover. To protect against this, ensure that you ...
9.9
Unauthenticated Access to Charging Station Websocket Endpoint
CVE-2026-20744
The charging station's websocket endpoint doesn't require authentication, allowing unauthorized users to potentially gain higher access levels. This could lead to unauthorized access to sensitive char...
9.3
Drupal Formatter Field: Malicious Data Injection Risk
DRUPAL-CONTRIB-2026-048 CVE-2026-12535
An attacker with permission to edit certain content in Drupal can inject malicious data into the Formatter Field. This can happen when the core JSON:API module is misconfigured. To stay safe, ensure o...
9.8
Drupal LocalGov Workflows Missing Authorization
CVE-2026-10768
A security issue in Drupal LocalGov Workflows allows unauthorized access to certain features. This affects versions 0.0.0 to 1.6.0 of the software. To stay secure, update to a fixed version of LocalGo...
9.8
Drupal Project Security Issue Unaddressed by Maintainer
DRUPAL-CONTRIB-2026-045 CVE-2026-11913
A known security issue in Drupal remains unfixed by the project's maintainer, leaving users vulnerable. To maintain the project and fix the issue, you'll need to take over ownership and follow Drupal'...
9.8
LocalGov Workflows - Unauthorized Access to Data
CVE-2026-10768
LocalGov Workflows, a Drupal module, has a security issue that lets unauthorized users access sensitive information. This affects versions 0.0.0 to 1.6.0. Update to the latest version to fix this issu...
9.8
Drupal Basket module: Unsanitized data allows code execution
DRUPAL-CONTRIB-2026-038 CVE-2026-9726
The Drupal Basket module is used for e-commerce and checkout on Drupal sites. If an attacker injects malicious data, they may be able to execute arbitrary code on the site, potentially leading to unau...
9.8
miniOrange WordPress Plugin Allows Attackers to Take Over Admin Accounts
CVE-2026-12761
The miniOrange Social Login plugin for WordPress, used for social media login and registration, has a security issue that lets attackers gain full access to admin accounts. This happens when an attack...
9.8
miniOrange OAuth SSO Client: Password Recovery Bypass Risk
CVE-2026-57807
A security issue in miniOrange's OAuth Single Sign On (SSO) software allows attackers to bypass authentication using an alternative method. This affects all versions of the OAuth SSO client up to 38.5...
9.8
Debian Linux: Unauthenticated Remote Code Execution
DEBIAN-CVE-2026-57156
A security issue in Debian Linux's package manager allows an attacker to execute malicious code without needing permission. This could happen if a user installs a malicious package from an untrusted s...
9.9
FreeRDP: Malicious RDP peer can cause memory corruption
CVE-2026-57156
FreeRDP clients are affected. An attacker can exploit this vulnerability to cause memory corruption, potentially leading to crashes or other security issues. Update to version 3.28.0 or later to fix t...
8.6
MCP Server Kubernetes: Argument Injection Risk in kubectl Tools
CVE-2026-61459
MCP Server Kubernetes versions before 3.9.0 have a security risk in certain tools (kubectl_get, kubectl_describe, kubectl_delete). This means an attacker could trick the system into sending sensitive ...
9.3
SEM-PMP Allows Unwanted Code Execution
CVE-2026-5801
A security issue in SEM-PMP allows hackers to execute malicious commands. This affects SEM-PMP versions up to April 23, 2023. To stay safe, update SEM-PMP to the latest version or consider replacing i...
9.8
MobilMen 20T Unsecured SQL Commands
CVE-2026-2397
The MobilMen 20T software from Adam Retail Automation Ltd. has a security weakness that allows an attacker to manipulate database commands. This can lead to unauthorized access to sensitive data or di...
9.8
IntelliJ IDEA Path Traversal Vulnerability in Workspace ID Handling
CVE-2026-59792
Old versions of IntelliJ IDEA allow an attacker to execute code on your computer by manipulating project file paths. This is a security risk because it could allow unauthorized access to your system. ...
9.8
Vikunja before 2.2.1 exposes sensitive share links and attachments
CVE-2026-56765
Vikunja, a task management software, has a security flaw that lets unauthorized users access sensitive share links and attachments. This could lead to unauthorized access to confidential files and dat...
9.3
Linux Kernel: Fragment Merging Vulnerability Resolved
CVE-2026-53363
A vulnerability in the Linux kernel's fragment merging feature has been fixed. This issue could allow hackers to manipulate encrypted data, potentially leading to unauthorized access. Affected systems...
9.8