Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 14 July 2026

RSS

2347 vulnerabilities published on 14 July 2026

Severity:
ColdFusion: Unauthorized Access to Sensitive Data
CVE-2026-48321
A security issue in ColdFusion could allow an attacker to access sensitive data or make changes without permission. This could happen without the user's knowledge or action. To protect your system, up...
10.0
Debian Linux: Unauthenticated Remote Code Execution
DEBIAN-CVE-2026-54433
Debian Linux systems are at risk of unauthorized code being executed remotely. This means an attacker could gain control of a Debian Linux system without needing a password. To protect your system, en...
10.0
Roundcube Webmail: Malicious Email Can Hijack User Sessions
CVE-2026-54433
If you use Roundcube Webmail, a hacker can create a malicious email that can take control of your account without you even opening it. This is a serious issue because it allows an attacker to access y...
10.0
Rockwell Automation 1715 Redundant IO - Unsecured Debug Port Exposes Device to Hackers
CVE-2026-10577
An unsecured port on Rockwell Automation's 1715 Redundant IO device allows hackers to access sensitive commands remotely. This could lead to data loss, system crashes, or unauthorized changes to the d...
10.0
YouTrack: Unauthorized Access to Administrative Features
CVE-2026-62422
An old version of YouTrack allowed attackers to bypass authentication and gain access to administrative features by directly accessing the database. This could have allowed hackers to make changes to ...
10.0
Opcenter X: Unauthenticated User Impersonation via JWT Forgery
CVE-2026-56451
Opcenter X versions prior to V2604 do not properly check JWT headers. This allows an attacker to create fake user identities, potentially gaining full access to the application. Update to version V260...
10.0
SonicWall SMA1000 Appliances Can Make Unwanted Internet Requests
CVE-2026-15409
A security issue in SonicWall SMA1000 Appliances could allow an attacker to trick the device into accessing unauthorized websites or services. This could potentially lead to data theft or other malici...
10.0 KEV
ColdFusion SQL Injection Vulnerability Allows Code Execution
CVE-2026-48324
ColdFusion software is at risk of being exploited by malicious code that can execute arbitrary actions with the current user's permissions. This vulnerability can be exploited without user interaction...
9.9
ColdFusion Code Injection Vulnerability Allows Malicious Code Execution
CVE-2026-48322
ColdFusion software contains a vulnerability that allows an attacker to execute malicious code on a user's system. This means an attacker could potentially take control of a user's account and access ...
9.9
ColdFusion allows malicious code execution
CVE-2026-48319
ColdFusion has a security flaw that could let hackers run unauthorized code on your server. This could happen without anyone needing to click on anything, making it a serious concern. You should updat...
9.9
ColdFusion allows unauthorized access to sensitive files
CVE-2026-48318
ColdFusion's security has been compromised, allowing an attacker to access sensitive files without permission. This could lead to data theft or unauthorized changes. To protect your system, update Col...
9.9
ColdFusion User Input Validation Error Allows Code Execution
CVE-2026-48284
ColdFusion users are at risk of having malicious code executed on their accounts if an attacker sends them a malicious input. This can happen without the user's knowledge or action. To protect yoursel...
9.9
FacturaScripts: Malicious File Upload via Client-Supplied Filename
GHSA-hgjx-r89m-m7v4
An attacker can upload files outside the intended directory by submitting a filename with '../' segments. This allows them to potentially execute malicious code on your server. To fix this, ensure tha...
9.9
FacturaScripts: Password and Session Data Exposed via API Filter
GHSA-5qmh-x653-g8qj CVE-2026-45262
FacturaScripts' REST API has a security flaw that can expose sensitive information, including passwords and session data. This can happen when an attacker sends a specially crafted request to the API....
9.9
Windows VMSwitch Privilege Elevation Over Network
CVE-2026-57092
An attacker with authorized access to Windows VMSwitch over a network can potentially gain elevated privileges. This affects Windows systems and can be exploited by authorized users. To protect your n...
9.9
SAP NetWeaver ABAP Memory Corruption Risk: Unauthorized Access
CVE-2026-44747
SAP NetWeaver ABAP systems are at risk of memory corruption, which could lead to unauthorized data access or system unavailability. This is a serious issue that could compromise confidentiality, integ...
9.9
Ciena Navigator and Blue Planet Authentication Bypass Risk
CVE-2026-5270
Ciena Navigator and Blue Planet products may allow unauthorized access. This is a serious security risk because attackers can bypass security checks and gain access to sensitive areas without a passwo...
9.8
Ciena Navigator NCS and MCP default passwords leave systems at risk
CVE-2026-5269
Ciena's Navigator Network Control Suite and Manage Control Plan have hidden system accounts with easily guessable passwords. These accounts don't have much power on their own, but an attacker could us...
9.8
OpenHTJ2K: Buffer overflow lets attackers run malicious code
CVE-2026-51808
A vulnerability in OpenHTJ2K versions 0.18.4 and earlier allows attackers to run unauthorized code on a system. This could lead to data theft or system compromise. Update to the latest version of Open...
9.8
OpenHTJ2K v.0.18.4 and earlier allows code execution via malicious data
CVE-2026-51807
OpenHTJ2K, a Java library for handling JPEG 2000 files, has a security issue that could allow an attacker to run unauthorized code on a system by sending it a specially crafted file. This is a serious...
9.8
Twig Template Language Allows Unsecured Template Rendering
DEBIAN-CVE-2026-46634
A security issue in Twig's template language allowed a malicious template to bypass security checks and render other templates without proper security enforcement. This issue has been fixed in version...
9.4
Twig: Using template_from_string() can bypass security sandbox
GHSA-24x9-r6q4-q93w CVE-2026-46634
A security setting in Twig allows certain templates to access sensitive features, which can be exploited by attackers. To prevent this, Twig developers should avoid using the template_from_string() fu...
7.7
Twig: PHP Code Injection via Malformed Template Names
GHSA-7p85-w9px-jpjp CVE-2026-46633
A security flaw in Twig allows attackers to inject malicious PHP code into templates. This can lead to unauthorized access to sensitive data and potentially allow attackers to execute code on the serv...
8.7
Debian: Unpatched OpenSSL in Debian 12 Exposes Data
DEBIAN-CVE-2026-46633
Debian 12 users are at risk of having sensitive data exposed due to an unpatched OpenSSL issue. This vulnerability allows an attacker to intercept and read sensitive information, such as passwords and...
9.4
Aetopia DAM v1.0.0: Uncontrolled Code Execution via Project Fields
CVE-2026-38450
An attacker can use Aetopia Digital Asset Management DAM version 1.0.0 to run malicious code on a vulnerable server. This is a serious security risk because it could allow an attacker to access sensit...
9.8