Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 12 July 2026
RSS546 vulnerabilities published on 12 July 2026
Severity:
Comfast CF-WR631AX V3 webmgnt system_wl_upload_pic_file command injection
CVE-2026-15511
A security issue exists in Comfast CF-WR631AX V3 routers with outdated firmware. An attacker could potentially inject malicious commands into the router's system, allowing them to take control of the ...
8.9
Zephyr IPv4 Address Parsing Allows Remote Code Execution
CVE-2026-10666
A bug in Zephyr's IPv4 address parsing code allows an attacker to execute malicious code on a connected device. This can happen when a device connects to a network or receives a DNS response. To fix t...
9.8
Flowise - Default Secrets in JWT Authentication Exposed
CVE-2026-56271
Flowise versions 3.0.13 and earlier use weak default secrets in its JWT authentication system. This allows attackers to create fake authentication tokens, potentially impersonating administrators or o...
9.3
Flowise: Weak Default JWT Secrets Expose User Authentication
GHSA-cc4f-hjpj-g9p8
Flowise has weak default settings for JSON Web Tokens (JWTs) that can be exploited by attackers to impersonate any user, bypassing authentication and potentially gaining admin access. This is a critic...
9.3
Crawl4AI - Malicious files can be written to server
CVE-2026-56260
PYSEC-2026-596
The Crawl4AI software before version 0.8.7 allows attackers to write malicious files to the server. This could cause the server to crash or become unusable. To fix this, update Crawl4AI to version 0.8...
9.2
Capgo - Demoted Admins Can Delete Bundles Indefinitely
CVE-2026-56241
GHSA-rvvc-rvxv-qcrh
A security issue in Capgo versions before 12.128.2 allows demoted administrators to keep deleting certain types of files, even after they've lost their full admin privileges. This could be exploited b...
8.9
Joomla! Core - Unauthorized Custom Field Creation
CVE-2026-48958
BIT-joomla-2026-48958
The Joomla! core is vulnerable to a security issue that allows anyone to create custom fields without proper permission. This can lead to data tampering and unauthorized changes to the website. To fix...
6.4
Joomla! Comprises Unauthorized Data Access
CVE-2026-48957
BIT-joomla-2026-48957
An improper access check in Joomla!'s com_privacy module allows unauthorized users to view sensitive data. This is a serious security risk as it can lead to data exposure. To protect your site, update...
6.4
Joomla! Core - Users Can Download Inaccessible Contact Data
CVE-2026-48948
BIT-joomla-2026-48948
A security issue in Joomla!'s contact manager allows users to download contact information that they shouldn't have access to. This can lead to sensitive information being exposed to unauthorized indi...
6.4
luci-app-upnp Stored XSS via UPnP Port Mapping
CVE-2026-61875
A stored cross-site scripting vulnerability exists in luci-app-upnp, allowing attackers to inject malicious code on devices that render the UPnP or Status pages. This could lead to unauthorized access...
8.7
OpenWrt luci-app-samba4 allows unauthorized code execution
CVE-2026-59260
The OpenWrt luci-app-samba4 software has a security issue that allows attackers to run unauthorized code on the system. This can happen when an attacker uses a valid login to gain access to the system...
8.7
LuCI DHCP Lease Hostname Cross-Site Scripting
CVE-2026-61876
An attacker on the same network can inject malicious code into LuCI's DHCP lease pages, potentially allowing them to take control of an administrator's browser. This vulnerability affects LuCI version...
9.4
TRENDnet TEW-821DAP: Remote Code Execution Through Buffer Overflow
CVE-2026-15483
A vulnerability in an older version of the TRENDnet TEW-821DAP router allows hackers to remotely execute code on the device. This only affects devices that are no longer supported by the manufacturer,...
8.7
TRENDnet TEW-821DAP: Remote Attack via Buffer Overflow
CVE-2026-15484
A remote attacker can exploit a buffer overflow vulnerability in the TRENDnet TEW-821DAP router, which is no longer supported by the manufacturer. This means the company will not provide any security ...
8.7
Trendnet TEW-635BRM IPoA WAN Setup Allows Remote Attack
CVE-2026-15481
A security risk exists in older Trendnet TEW-635BRM routers. An attacker could potentially take control of the router from a distance, using a publicly available exploit. If you're still using this ro...
7.4
Trendnet TEW-635BRM: Remote Code Execution through Web Service
CVE-2026-15480
A vulnerability in an older version of Trendnet's TEW-635BRM router allows a hacker to execute code remotely, potentially taking control of the device. This affects devices that are no longer supporte...
7.4
Capgo - Attackers Can Delete Users' Email Login Access
CVE-2026-56313
GHSA-x3vq-34gg-cwq7
An attacker with permission can delete users' email login credentials in other organizations, forcing them to switch to the attacker's login system or reset their password. This affects Capgo users wh...
8.6
Capgo Email Change Allows Unauthorized Account Access
CVE-2026-56308
GHSA-9px4-w25f-mvm4
Capgo versions prior to 12.128.2 have a security issue that allows attackers to change a user's email address, potentially gaining control of account recovery and bypassing multi-factor authentication...
8.6
hcr707305003 shiroiAdmin File Upload Without Limits
CVE-2026-15488
The hcr707305003 shiroiAdmin software has a security issue that allows attackers to upload files without any restrictions. This means they can upload malicious files that could potentially harm your s...
8.4
Microsoft Edge (Chromium-based) Privilege Hike Risk
CVE-2026-58596
An unauthorized attacker can gain more access to your network by exploiting a weakness in Microsoft Edge (Chromium-based). This could allow them to do more harm to your system and data. Update your Mi...
8.3
Capgo - Demoted Admins Still Have Deletion Privileges
CVE-2026-56241
A security issue in Capgo versions before 12.128.2 allows attackers to delete sensitive files in an organization even after the attacker's admin privileges have been removed. This is because the syste...
7.2
Capgo - Unauthenticated Disclosure of Financial Metrics
CVE-2026-56238
GHSA-73rv-fpp7-r3r4
Capgo versions prior to 12.128.2 allow unauthenticated access to sensitive financial data, including revenue and customer counts. This means that anyone can view this information without needing a log...
8.3
Docker Server: LLM Credential Exfiltration via Malicious URLs and Environment Variables
GHSA-f989-c77f-r2cq
A vulnerability in the Docker API server allows attackers to steal sensitive credentials and authentication keys. This can happen when an attacker controls the URL where the server sends requests or w...
8.8
Docker Server: LLM Credential Exfiltration via Malicious URLs and Environment Variables
GHSA-f989-c77f-r2cq
CVE-2026-56259
A vulnerability in the Docker API server allows attackers to steal sensitive credentials and authentication tokens by manipulating URLs and environment variables. This can lead to unauthorized access ...
8.6
Crawl4AI LLM Credential Exposure via Malicious API Calls
CVE-2026-56259
Crawl4AI versions before 0.8.8 contain a security flaw that allows attackers to steal sensitive credentials. This can happen if an attacker sends malicious API requests to the Crawl4AI server. To prot...
8.8