Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 15 July 2026
RSS914 vulnerabilities published on 15 July 2026
Severity:
NocoBase: Unauthenticated SQL Injection Risk in In-App Messages
CVE-2026-52887
NocoBase's in-app messaging feature allows attackers to inject malicious SQL code. This could potentially give an attacker control over a database and allow them to execute unauthorized commands. To f...
10.0
9router: Unauthenticated Remote Code Execution via Unprotected Routes
GHSA-fhh6-4qxv-rpqj
CVE-2026-46339
The 9router software exposes unauthenticated API endpoints that can be used to execute arbitrary OS commands without any prerequisites or credentials. This vulnerability exists because the authenticat...
10.0
NocoBase: Unsecured SQL Input Allows Malicious Code Execution
CVE-2026-52887
GHSA-p849-8hwh-84j9
A security issue in NocoBase's notification plugin could allow an authenticated user to execute malicious code on the database. This could lead to unauthorized access and data theft. NocoBase has rele...
10.0
Metabase: Malicious Files Can Run on Server via Snowflake Connection
CVE-2026-50148
An attacker can exploit a flaw in the Snowflake database connection to write malicious files on the Metabase server. This can lead to unauthorized code execution, potentially compromising the server. ...
10.0
iperf Buffer Overflow in Authentication Module
JLSEC-2026-762
The iperf authentication module is vulnerable to a buffer overflow, which could allow an attacker to execute malicious code. This affects users who run iperf, especially in network testing and benchma...
10.0
Wazuh Manager - Malicious Agent Can Delete or Alter SIEM Data
CVE-2026-56699
A vulnerability in Wazuh Manager before version 5.0.0-beta3 allows an enrolled agent to delete or alter data in the SIEM system. This could lead to deleted alerts, tampered data, or other security inf...
10.0
Root's axios Library Allows Remote Code Execution
ROOT-APP-NPM-CVE-2026-40175
The axios library used in some Root applications contains a security flaw that could allow an attacker to run malicious code on your server. This could happen if an attacker injects malicious data int...
10.0
Wekan: Malicious Avatar Upload Can Execute Commands
CVE-2026-52891
Wekan, an open source project management tool, allows attackers to execute commands on the server by uploading a malicious avatar with special characters. This can lead to unauthorized access and syst...
9.9
Wekan: Hackers can execute server commands via uploaded avatar
CVE-2026-52891
GHSA-35j7-h385-2q9g
Wekan's avatar upload feature allows hackers to execute server commands if they upload a file with malicious characters. This is a security risk because it could allow hackers to take control of your ...
9.9
n8n-MCP: Cross-Tenant Access to Workflow Backups in Multi-Tenant Deployments
GHSA-j6r7-6fhx-77wx
CVE-2026-54052
In multi-tenant n8n-MCP deployments, an authenticated tenant could access and delete other tenants' workflow backup data. This is fixed in version 2.56.1. To protect your data, upgrade to the latest v...
9.9
DataEase: Malicious User Access to Sensitive Data
CVE-2026-46684
GHSA-gp6v-f7mm-458v
DataEase's data visualization and analysis tool had a security issue that could allow attackers to create fake user accounts with access to sensitive data. This is a concern because it could lead to u...
9.9
Penpot: Unsecured Account Takeover via Invitation Token
CVE-2026-44986
Penpot, a design tool, had a security weakness that allowed a registered user to take over any non-blocked account by using an invitation token. This meant that an attacker could gain access to sensit...
9.9
axios for Root:npm: Unauthenticated Data Exposure through Request Headers
ROOT-APP-NPM-CVE-2025-62718
The axios package for Root:npm allows an attacker to access sensitive data without needing a valid login. This issue affects users of Root's npm package and has been fixed in a newer version, which sh...
9.9
Wekan: Unauthenticated Account Takeover via Spoofed IP Address
CVE-2026-55652
An attacker can gain full access to any Wekan account, including admin accounts, by sending a fake IP address. This can happen if you're using Wekan's header-login feature with trusted IP addresses. T...
9.8
LiteLLM 1.18.10 MCP Server Creation Allows Malicious Code Execution
CVE-2026-30623
A security issue exists in LiteLLM 1.18.10 that could allow an attacker to execute malicious code on your server with the same permissions as the LiteLLM process. This can happen if an attacker is abl...
9.8
xszyou Fay 4.3.1 allows attackers to run unauthorized server commands
CVE-2026-30618
A publicly accessible management interface in xszyou Fay 4.3.1 can be exploited by an attacker to run unauthorized server commands. This allows the attacker to take control of the server, which could ...
9.8
Open Source GPT Researcher v3.3.7 allows arbitrary command execution
CVE-2025-65720
Attackers can trick users into opening a malicious webpage, giving them control over the system. This is a serious security risk because it allows attackers to take control of your computer and steal ...
9.8
Tenda AC10 v3 firmware allows permanent DoS or remote code execution
CVE-2026-51380
A security issue in the Tenda AC10 v3 router's firmware (version V03.03.16.09) could allow hackers to shut down the router or take control of it. This affects anyone using this router, and it's essent...
9.8
9router's Default Secret Allows Unauthenticated Access
GHSA-jphh-m39h-6gwx
CVE-2026-49352
9router's default secret is hardcoded and publicly known, allowing unauthorized users to access the dashboard and API if the server's JWT secret is not set. This vulnerability affects many public 9rou...
9.8
Pegatron Tdelo64.sys Privileged Hardware Access Exposure
CVE-2026-14960
A security issue affects Pegatron's Tdelo64.sys driver, which allows unauthorized access to sensitive hardware features. This could be exploited by an attacker on the same local network, potentially c...
9.8
Oracle E-Business Suite Payments File Transmission Compromise
CVE-2026-46817
The Oracle E-Business Suite's Payments component has a vulnerability in its File Transmission feature. This means an attacker with internet access can potentially take control of the Payments system, ...
9.8
KEV
AVideo YPTSocket Plugin: Unauthenticated Stored DOM XSS
GHSA-8whc-2wmv-ww35
CVE-2026-54458
The AVideo YPTSocket plugin has a security flaw that allows an attacker to inject malicious code into the website's content, potentially affecting administrators viewing the online-users panel. This c...
9.6
OpenWrt odhcpd/LuCI: Unauthenticated DHCPv6 Client Injects Malicious Code
CVE-2026-62948
An attacker can inject malicious code into the OpenWrt admin interface, potentially allowing them to steal sensitive information or take control of the device. This is fixed in version 25.12.5. Users ...
9.6
Outdated @better-auth/sso Plugin Allows Unauthorized Server Access
GHSA-5rr4-8452-hf4v
CVE-2026-53513
If you're using an outdated version of the @better-auth/sso plugin, an attacker can access your server by tricking your system into making unauthorized requests. This can happen even if the attacker d...
9.6
Grav before 1.0.4: Password Reset Token Leaked via Fake Email
CVE-2026-61451
Grav users are at risk of account takeover if an attacker sends a fake password reset email with a link to a server they control. This can happen if an attacker sends a malicious request to the Grav A...
9.4