Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 13 July 2026

RSS

1406 vulnerabilities published on 13 July 2026

Severity:
Realtyna Organic IDX Plugin Allows Remote Code Execution
CVE-2026-57811
The Realtyna Organic IDX plugin, used for real estate listings, has a security flaw that could allow hackers to inject and execute malicious code on a website. This could lead to unauthorized access a...
10.0
Aimogen Pro allows uploading malicious files
CVE-2026-57719
An attacker can upload malicious files to the Aimogen Pro platform, which could lead to unauthorized actions or data corruption. This affects users of Aimogen Pro versions up to 2.8.3. It's recommende...
10.0
DIRAC FileCatalog DatasetManager SQL Injection Allows Remote Code Execution
GHSA-m4m7-4cw8-62j6 CVE-2026-61667
The DIRAC FileCatalog DatasetManager has a security flaw that lets an authenticated user execute malicious code on the system. This is due to an unsecured SQL query that can be manipulated by a user. ...
9.9
DIRAC RequestManager allows authenticated users to run server commands
GHSA-9jpv-c7p4-997x CVE-2026-45579
An authenticated user can run commands on the DIRAC server, which allows them to access sensitive information, delete evidence, and potentially take control of the system. This is due to the use of ev...
9.9
WoowBot Pro Max allows uploading malicious files
CVE-2026-57710
WoowBot Pro Max, a software used to manage cloud services, has a security issue that allows users to upload files that could potentially harm the system. This is a concern because malicious files coul...
9.9
Path Traversal Vulnerability in SureDash
CVE-2026-57401
The SureDash software has a security issue that allows hackers to access files they shouldn't be able to. This is a concern because sensitive data could be stolen or modified. To stay safe, update Sur...
9.9
D-Link DIR-1253 Privilege Escalation via etc/shadow File
CVE-2026-52533
The D-Link DIR-1253 router's etc/shadow file is vulnerable to unauthorized access. This could allow an attacker to gain elevated privileges on the router, potentially allowing them to make changes to ...
9.8
Shenzhou Shihan Video Conference System v.1.0 allows remote code execution
CVE-2026-51821
A security flaw in the Shenzhou Shihan Video Conference System v.1.0 allows a malicious user to potentially take control of the system by sending specially crafted data to the /user/getUserLogin endpo...
9.8
OpENer Memory Corruption Risk in Explicit Messages
CVE-2026-51540
The OpENer messaging software is at risk of a critical memory corruption issue when handling certain types of messages. This could lead to unexpected crashes or data loss. Update to the latest version...
9.8
9Router 0.4.41 - Unauthenticated Access to Provider API
CVE-2026-59801
An attacker can access and manipulate provider connections without a password, potentially exposing sensitive information and disrupting service. This vulnerability affects 9Router versions up to 0.4....
9.3
Rejetto HFS 3.0.0-3.2.0: Administrator Session Cookie Forgery Risk
CVE-2026-61500
Rejetto HFS, a web file manager, has a security flaw that allows an attacker to steal an administrator's session and take control of the server. This can happen if an attacker observes a few login att...
9.3
Perl Storable versions before 3.41 can crash due to crafted data
CVE-2026-57433
Versions of Perl's Storable module before 3.41 can crash if it's given a specially crafted file. This can happen when the module tries to deserialize data that's been tampered with. To fix this, updat...
9.8
Debian Linux: Privilege Escalation via Sudo Misconfiguration
DEBIAN-CVE-2026-57433
A misconfiguration in Debian Linux's sudo package can allow unauthorized users to gain elevated privileges, potentially allowing them to access sensitive data or take control of the system. This issue...
9.8
Perl Storable Overflow Allows Malicious Code Execution
UBUNTU-CVE-2026-57433
Versions of Perl Storable before 3.41 have a bug that can allow attackers to execute malicious code. This affects systems that use Perl Storable to store and retrieve data. To fix this, update Perl to...
9.8
CKAN Datastore Search Allows Access to Private Data
GHSA-h7j7-3rx6-xvcg CVE-2026-42031 PYSEC-2026-2417
Attackers can access sensitive data and system information if they exploit a vulnerability in CKAN's Datastore Search feature. This issue has been fixed in CKAN versions 2.10.10 and 2.11.5. To protect...
8.6
Alerta Search API allows attackers to inject malicious SQL code
CVE-2026-34400 GHSA-8prr-286p-4w7j PYSEC-2026-2341
A security flaw in the search feature of the Alerta monitoring tool allowed hackers to inject malicious code, potentially exposing sensitive data. This has been fixed in version 9.1.0, so update to th...
7.8
Vitec Flamingo 4.12.2 Allows Unauthenticated Command Execution
CVE-2026-61498
The Vitec Flamingo 4.12.2 software has a security issue that lets hackers execute system commands without needing a password. This is a serious risk because hackers can access sensitive system setting...
9.3
Vitec Flamingo 4.12.2 Unauthenticated Command Execution via ping.php
CVE-2026-60121
The Vitec Flamingo 4.12.2 software has a security flaw that allows unauthorized access to the system. This means an attacker can execute commands on the system without needing a password, potentially ...
9.3
Directorist 8.8.2 Deserialization of Untrusted Data Risk
CVE-2026-59518
The Directorist software has a security issue that could allow an attacker to inject malicious code. This affects versions up to 8.8.2, which means you should update to a newer version to stay secure....
9.8
MailOptin Privilege Escalation via Incorrect Privilege Assignment
CVE-2026-57813
The MailOptin plugin for WordPress has a security issue that allows an attacker to gain elevated privileges. This means they could potentially access and modify sensitive data or settings. To fix this...
9.8
Grand Photography Untrusted Data Deserialization Risk
CVE-2026-57770
Grand Photography versions 5.7.8 and below are at risk of object injection attacks. This means an attacker could potentially inject malicious code into the application, leading to unauthorized actions...
9.8
Untrusted Data Can Inject Malicious Objects into RT-Theme 18
CVE-2026-57744
The RT-Theme 18 | Extensions rt18-extensions may allow an attacker to inject malicious code by sending untrusted data. This affects websites using the affected extension. To protect your site, update ...
9.8
Axiomthemes 777 Triple-Seven: Untrusted Data Injection Risk
CVE-2026-57738
A bug in the Axiomthemes 777 Triple-Seven software allows attackers to inject malicious code. This issue affects versions of the software from unknown to 1.13.0, which means anyone using these version...
9.8
Kirki Themeum Kirki: Untrusted Data Causes Object Injection
CVE-2026-57724
Kirki, a plugin used in WordPress themes, has a vulnerability that allows attackers to inject malicious objects. This could potentially lead to unauthorized access or data tampering. Update Kirki to t...
9.8
WAGO System I/O Field devices expose internal diagnostics during startup
CVE-2026-4769
WAGO System I/O Field devices have a hidden diagnostic mode that becomes accessible for a short time during startup. This allows an attacker to access the device's internal processes without a passwor...
9.3