Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 17 July 2026
RSS953 vulnerabilities published on 17 July 2026
Severity:
PrestaShop ps_facetedsearch: Unauthenticated Remote Code Execution
GHSA-m5f5-28qr-9g9r
CVE-2026-54159
A vulnerability in PrestaShop's ps_facetedsearch module allows an attacker to execute code on your server without needing a login. This can happen if you're using a vulnerable version of the module an...
10.0
IBM Langflow OSS: Arbitrary File Writes via Malicious HTTP Response
CVE-2026-8859
IBM Langflow OSS versions 1.0.0 through 1.10.0 have a security issue that could allow an attacker to write files to unintended locations on your server. This could happen if an attacker controls an ex...
9.9
IBM Langflow OSS Privilege Escalation and Command Execution
CVE-2026-8635
Authenticated users on IBM Langflow OSS can gain superuser access and execute system commands, putting sensitive data at risk. This is a critical issue that requires immediate attention from administr...
9.9
IBM Langflow OSS disk caching allows malicious code execution
CVE-2026-8476
IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a critical security flaw in their disk caching system. This means an attacker could potentially take control of the entire system if they can man...
9.9
IBM Langflow: Custom Component Validation Bypass
CVE-2026-9135
IBM Langflow versions 1.0.0 to 1.10.0 have a security flaw that allows attackers to inject malicious code into the system. This can happen when a user with permission to create flows embeds malicious ...
9.9
IBM Langflow: Remote Code Execution via User-Submitted Code
CVE-2026-8481
IBM Langflow's code validation API allows users to execute their own Python code, potentially running malicious system commands with the server's full privileges. This affects versions 1.0.0 through 1...
9.9
Langflow Exposes Hard-Coded Credentials
CVE-2026-13446
IBM Langflow's open-source version contains a serious security risk: its use of hard-coded passwords and keys. This means that anyone with access to the software can see these sensitive credentials, w...
9.8
CodeIgniter4 File Uploads Can Allow Malicious PHP Files
GHSA-2gr4-ppc7-7mhx
CVE-2026-48062
CodeIgniter4, a popular web development framework, has a security issue that allows malicious PHP files to be uploaded. This can happen if your application allows users to upload files and relies on t...
9.8
IBM Langflow OSS: Unauthenticated users can trigger any flow
CVE-2026-8505
IBM Langflow OSS versions 1.0.0 through 1.10.0 have a security issue where anyone can trigger any flow without needing a password. This could allow an attacker to execute malicious code. To stay safe,...
9.8
WordPress 6.9.x and 7.0.x - Remote Code Execution Risk
CVE-2026-63030
Certain versions of WordPress are vulnerable to a remote code execution attack through its REST API. This can happen if an attacker exploits a SQL injection flaw in the way WordPress handles certain q...
9.8
IBM Langflow: Unauthenticated Access to Administrative Features
CVE-2026-9103
IBM Langflow OSS versions 1.0.0 to 1.10.0 have a security issue that allows unauthorized access to administrative features. This can happen if a network attacker uses a feature called auto-login. To p...
9.8
IBM Langflow Unauthenticated User Registration Allows Remote Code Execution
CVE-2026-9202
IBM Langflow users are at risk of remote code execution due to a security flaw that allows attackers to create new user accounts without authentication. This could allow an attacker to gain full contr...
9.8
IBM Langflow allows attackers to run code on default installations
CVE-2026-9198
IBM Langflow's default settings allow unauthorized users to run code on the system, posing a significant risk. This issue affects versions 1.0.0 through 1.10.0 of the software. To protect your system,...
9.8
GisLab Laboratory Management System SQL Injection Vulnerability
CVE-2026-8297
The GisLab Laboratory Management System is vulnerable to SQL injection attacks, which could allow unauthorized access to sensitive data. This affects versions 1.4.03 and later, up to 08072026. Users s...
9.8
Vimesoft Enterprise Video Platform Password Change Bypass
CVE-2026-12692
The Vimesoft Enterprise Video Platform has a weakness in its password change process. This means that a malicious user could potentially change someone else's password without needing to know the curr...
9.8
Libpve Storage Perl XXE Vulnerability Affects Proxmox Servers
CVE-2026-51080
The Libpve Storage Perl library, used by Proxmox servers, contains a vulnerability that allows attackers to inject malicious code. This could lead to unauthorized access or data theft. Users should up...
9.8
hplip Printer Drivers Need Security Update
RLSA-2026:40831
A security update is needed for hplip printer drivers to fix a previously incomplete patch. This affects HP printer users, who should update their drivers to prevent potential security risks. Update y...
9.8
Rootio-zlib on Root:Debian:11: Data Exposure
ROOT-OS-DEBIAN-11-CVE-2023-45853
The rootio-zlib package on Root:Debian:11 has a vulnerability that could allow attackers to access sensitive data. This is a serious issue because it could compromise the security of your system. To p...
9.8
Rootio-Imagemagick Allows Arbitrary Code Execution on Debian 11
ROOT-OS-DEBIAN-11-CVE-2023-34152
A security patch has been released for the Rootio-Imagemagick package on Debian 11. This patch fixes a vulnerability that could allow an attacker to run unauthorized code on a system. We recommend upd...
9.8
rootio-python3.9: Unauthenticated Remote Code Execution Risk
ROOT-OS-DEBIAN-11-CVE-2026-7210
The rootio-python3.9 package had a security issue that allowed an attacker to run malicious code without being authenticated. Root has released a patch to fix this issue, and it's essential to update ...
9.8
rootio-perl: Unauthorized access to system settings
ROOT-OS-DEBIAN-11-CVE-2026-8376
A security patch has been released for rootio-perl, a Perl library used by the Root framework. This patch fixes a vulnerability that could allow unauthorized access to system settings. Root users shou...
9.8
AIWU Plugin < 1.5.4 - Unauthenticated Access to Administrator Privileges
CVE-2026-9810
The AIWU plugin for WordPress doesn't properly check user access, allowing attackers to gain administrator privileges without logging in. This can lead to sensitive tasks being performed without permi...
9.8
Aimogen Pro <= 2.8.4: Unauthenticated Admin Account Creation
CVE-2026-15982
The Aimogen Pro plugin for WordPress allows unauthorized users to create admin accounts and gain full control of the website. This is a serious security risk because an attacker could use this to take...
9.8
HP Printer Drivers Need Security Update
RLSA-2026:40894
HP printer drivers contain a security issue that could allow an attacker to gain unauthorized access. This affects HP printers and multi-function peripherals. You should update the drivers to fix the ...
9.8
Bricksforge <= 3.1.8.6 - Unauthenticated Admin Account Creation via Public Form
CVE-2026-14956
A security issue in Bricksforge plugin for WordPress allows attackers to create new admin accounts without a password. This can happen if a public form is configured to allow user registration. To fix...
9.8