Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 16 July 2026

RSS

899 vulnerabilities published on 16 July 2026

Severity:
Jupyter Enterprise Gateway: Untrusted Environment Variables in Kubernetes Manifests
GHSA-cfw7-6c5v-2wjq CVE-2026-44182
Attackers can inject malicious data into Kubernetes manifests, potentially creating unauthorized resources like privileged pods. This is possible because Jupyter Enterprise Gateway interpolates untrus...
10.0
Jupyter Enterprise Gateway: Unauthorized Access to Kubernetes Cluster
GHSA-f49j-v924-fx9w CVE-2026-44181
The Jupyter Enterprise Gateway allows malicious users to execute code and access sensitive Kubernetes data, potentially compromising the entire cluster. This vulnerability affects any organization usi...
10.0
HireFlow: Attackers can access admin accounts
CVE-2026-45336
HireFlow's interview management system had a security issue that allowed attackers to gain access to admin accounts. This could have let unauthorized people control the system and make changes. HireFl...
10.0
Root:npm vm2 Remote Code Execution Risk
ROOT-APP-NPM-CVE-2026-47131
The Root:npm vm2 package had a security flaw that could allow an attacker to execute malicious code on a server. This could lead to unauthorized access or data theft. Root has released patched version...
10.0
Root:npm vm2 Package Unpatched on Older Versions
ROOT-APP-NPM-CVE-2026-44005
If you're using Root's npm package and haven't updated vm2 recently, you may be at risk of a security issue. This issue has been fixed by Root in newer versions of vm2. We recommend updating to the la...
10.0
Root:npm vm2 Vulnerability: Uncontrolled Memory Access
ROOT-APP-NPM-CVE-2026-44006
The @rootio/vm2 package in Root:npm has a memory access issue that could be exploited by attackers. This could lead to unauthorized data access or system crashes. Update to a fixed version of @rootio/...
10.0
Root VM2 Software Allows Unauthorized Access
ROOT-APP-NPM-CVE-2026-43997
A security patch has been released for the Root VM2 software to prevent unauthorized access. This affects users of Root's npm package. To stay secure, update to a patched version of the software as so...
10.0
Root VM2 Software Allows Unauthorized Access
ROOT-APP-NPM-CVE-2026-47137
The Root VM2 software has a security issue that could allow unauthorized access. This issue affects users who rely on the software for secure operations. To stay secure, update to the latest patched v...
10.0
Root VM2 Package Security Patch Needed
ROOT-APP-NPM-CVE-2026-47140
A security patch has been released for the Root VM2 package. This update is important for users of Root's npm package to protect against potential security risks. You should check for and install the ...
10.0
Root:npm @rootio/vm2 Unpatched, Update Required
ROOT-APP-NPM-CVE-2026-47208
The @rootio/vm2 package for Root:npm was previously vulnerable, but Root has since released a patch. Update to a fixed version to prevent potential security risks. Multiple patched versions are availa...
10.0
Frogman: Malicious code injected into Asterisk configuration
CVE-2026-46512
A bug in Frogman allowed attackers with special permissions to inject malicious code into the Asterisk configuration, potentially allowing them to control the phone system. This issue has been fixed i...
9.9
Zoom Workplace VDI Plugin for Windows - Unauthenticated Account Takeover
CVE-2026-53412
The Zoom Workplace VDI Plugin for Windows has a security weakness that could allow an unauthorized user to access and take control of a user's account through the network. This is a serious issue beca...
9.8
Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Versions 2.0.0rc1 and above prior to 3.3.0 have a pr...
GHSA-chq7-94j8-cj28 CVE-2026-44180
Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Versions 2.0.0rc1 and above prior to 3.3.0 have a prohi...
9.8
SQL Injection in ureport v2.2.9 Exposes Database Info
CVE-2026-38158
The /ureport/datasource/previewData component of ureport v2.2.9 has a security weakness that could allow unauthorized access to sensitive database information. This is a serious issue because it could...
9.8
Pheditor: Using default 'admin' password allows full application access
GHSA-p4h7-p9rj-2pq2 CVE-2026-55579
Pheditor's default 'admin' password is hardcoded and cannot be changed. This allows attackers to access the entire application, including file editing, uploading, and executing code. To fix this, chan...
9.8
Grafana OnCall 1.16.11 Unauthenticated Access via Plugin Install
CVE-2026-63087
An attacker can access Grafana OnCall without a password by sending a specific request to the plugin install endpoint. This allows them to create new users, revoke legitimate access, and redirect API ...
9.3
Yamcs Allows Remote Code Execution via Mission Database Algorithm Override
GHSA-vmwp-vh32-rj75 CVE-2026-46562
A vulnerability in Yamcs's Mission Database allows an attacker with ChangeMissionDatabase privilege to execute arbitrary code on the server. This could lead to unauthorized access or data tampering. T...
9.8
Yamcs Authentication Endpoint Lacks Rate Limiting
GHSA-w5r6-mcgq-7pq4 CVE-2026-44596
The Yamcs authentication endpoint does not limit the number of login attempts, making it vulnerable to brute-force attacks. This means an attacker can try many passwords without being blocked. To prot...
9.8
Outdated Epeg library in Image::EPEG for Perl
CVE-2026-3031
A library used in Image::EPEG for Perl is outdated and has not been updated since 2004. This can make it vulnerable to security issues and may not work properly with modern systems. It's recommended t...
9.8
Kopia: Unauthenticated Access via SSH Command Injection
GO-2026-5009 CVE-2026-45695 GHSA-2q4c-3mrw-63c3
Kopia's HTTP server allows unauthenticated access when started without a username or password. An attacker can inject malicious commands into the SSH connection, potentially executing arbitrary code a...
9.8
HCL DFXAnalytics: Unauthorized Access to User Accounts via Manipulated Responses
CVE-2026-56453
An attacker can intercept and alter server responses, potentially gaining access to user accounts. This affects the security of user data and authentication processes in HCL DFXAnalytics. To mitigate ...
9.8
Root:npm vm2: Untrusted Code Execution
ROOT-APP-NPM-CVE-2026-45411
A security patch has been released for the Root:npm vm2 package to prevent untrusted code from executing on your system. This affects users who have installed vm2 through Root:npm. You should update t...
9.8
Root VM2: Unauthenticated Access to Internal Services
ROOT-APP-NPM-CVE-2026-26332
The Root VM2 software had a security issue that allowed unauthorized access to internal services. This could have allowed attackers to access sensitive information or take control of the system. Root ...
9.8
Root VM2 Package Security Patch
ROOT-APP-NPM-CVE-2026-24118
A security patch has been released for Root's VM2 package. This patch fixes a security issue that could have allowed unauthorized access to Root's systems. To stay secure, update to the latest version...
9.8
Root:npm @rootio/vm2 - Unpatched Virtual Machine Software
ROOT-APP-NPM-CVE-2026-47210
The @rootio/vm2 package in Root:npm contains a security issue that could allow attackers to execute malicious code on virtual machines. This is a concern because it could be used to take control of th...
9.8