Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 18 July 2026

RSS

176 vulnerabilities published on 18 July 2026

Severity:
Fastify HTTP Proxy versions up to 11.5.0 expose internal paths
CVE-2026-16117
An attacker can access internal or administrative paths on a server protected by a Fastify HTTP proxy if the proxy is configured to rewrite a URL prefix that contains encoded characters. To fix this, ...
10.0
VMware Avi Load Balancer Authentication Bypass Risk
CVE-2026-47865
VMware Avi Load Balancer versions 31.1.1 to 31.2.2 and earlier versions 30.1.1 to 30.2.6 and 22.1.1 to 22.1.7 may allow unauthorized access to the system. This is a security risk because a malicious u...
9.8
SurrealDB fails to escape table and field names in export
CVE-2025-71392
A vulnerability in SurrealDB allows an authenticated user with the right permissions to inject malicious code into the database. This can lead to unauthorized access and even a complete takeover of th...
9.4
SurrealDB: Malicious Backup Import Allows Root Access
GHSA-ccj3-5p93-8p42 CVE-2025-71392
SurrealDB's backup export and import process can be exploited by a malicious user with OWNER or EDITOR roles to gain root access to the database. This risk is particularly high for SurrealDB instances...
9.4
SurrealDB accepts malicious data in signin and signup operations
CVE-2024-58362
SurrealDB versions 1.5.5 and earlier, and 2.0.0-beta versions before 2.0.0-beta.3, do not properly check data sent to signin and signup operations. This allows an attacker to execute unauthorized data...
8.7
SurrealDB before 1.0.1 allows unauthorized database access
CVE-2023-54366
SurrealDB versions prior to 1.0.1 have a default permission setting that allows anyone with database access to perform various operations on tables without explicit permission. This means attackers or...
8.7
OpenPLC_v3: Modbus Master Denial of Service via Heap Corruption
CVE-2026-11826
OpenPLC_v3, a software used for process control, has a security flaw that allows an attacker to crash the system and disrupt its operation. This issue affects the web interface and can be exploited by...
8.7
SurrealDB RPC API allows untrusted data in sign in and sign up operations
GHSA-64f8-pjgr-9wmr CVE-2024-58362
An attacker could use SurrealDB's RPC API to gain access to sensitive data and perform actions on a user's account if the API is exposed to untrusted users. This is possible if the SurrealDB owner has...
9.4
SurrealDB: All Users Have Full Access to Unsecured Tables
GHSA-x5fr-7hhj-34j3 CVE-2023-54366
Any user who can access SurrealDB can create, read, update and delete data in tables without explicit permissions. This is a concern for public-facing SurrealDB instances where anyone can access the d...
9.4
Shibby Tomato 1.28 Router Configuration Data Exposure
CVE-2026-16096
A security flaw in Shibby Tomato 1.28 allows hackers to access sensitive router configuration data remotely. This can lead to unauthorized changes to the router settings. We recommend updating to a ne...
8.7
Shibby Tomato Scheduler Name Handler stack overflow risk
CVE-2026-16097
The Shibby Tomato 1.28 Scheduler Name Handler has a vulnerability that could allow an attacker to overflow the system's memory, potentially leading to system crashes or unauthorized access. This issue...
8.7
Shibby Tomato 1.28: Remote Code Execution through Out-of-Bounds Write
CVE-2026-16095
A flaw in Shibby Tomato's setup process allows a remote attacker to potentially execute malicious code on the router. This issue affects users who have not updated to a newer version of the software, ...
8.7
Red Hat Hardened Images RPMs Security Fix for Linux
RHSA-2026:39952
Red Hat Hardened Images, used for secure Linux containers, has been updated to fix security issues and improve performance. This update is important for organizations using these images, as it ensures...
8.8
VMware Avi Load Balancer allows unauthorized access
CVE-2026-47871
The VMware Avi Load Balancer has a security flaw that allows a malicious user with a valid account to access parts of the system they shouldn't be able to. This could lead to unauthorized changes or d...
8.8
Stored Cross-Site Scripting in Parisneo Lollms Direct Messages
CVE-2026-12228
A vulnerability in Parisneo Lollms allows an attacker to send malicious messages to another user's inbox. This could lead to the attacker taking control of the victim's account, accessing sensitive in...
8.7
Fastify Reply-From URL Cache Key Issue
CVE-2026-16158
Fastify Reply-From versions 8.3.1 to 12.6.4 have a bug that can cause data to be accessed from the wrong server. This can happen when using the default settings. To fix the issue, upgrade to version 1...
8.7
Fastify HTTP Proxy allows attackers to bypass security settings
CVE-2026-15631
The Fastify HTTP Proxy software has a security flaw that allows attackers to access sensitive information by manipulating URLs. This issue affects versions 9.4.0 to 11.5.0 and can be exploited by cert...
8.7
VMware Avi Load Balancer allows unauthorized code execution
CVE-2026-47869
An attacker with access to the Avi Load Balancer can inject and run malicious code, potentially taking control of the system. This affects multiple versions of the software and can be mitigated by upg...
8.7
VMware Avi Load Balancer allows remote code execution
CVE-2026-47867
The VMware Avi Load Balancer is vulnerable to a security flaw that could allow an attacker to execute code remotely on the system. This means an attacker could potentially take control of the system. ...
8.7
SurrealDB: Malicious Scripting Input Can Read Memory or Run Code
GHSA-q3gg-m8hr-h4x4 CVE-2024-58366
SurrealDB servers with scripting enabled can be exploited if an attacker injects specific input into a scripting function. This could allow an attacker to read sensitive information or run malicious c...
8.9
SurrealDB before 1.1.1 allows attackers to read memory or execute code
CVE-2024-58366
An outdated version of SurrealDB contains a security flaw that lets attackers access sensitive information or take control of the database. This affects SurrealDB versions before 1.1.1, and it's essen...
9.0
VMware Avi Load Balancer Unauthorized Network Access
CVE-2026-47866
A malicious actor on the network can access some Avi Load Balancer features without permission. This could allow them to view or modify certain settings. VMware has released patches to fix this issue,...
8.3
QueryWeaver: Attackers can hijack existing accounts via email
CVE-2026-10130
An attacker can steal an existing QueryWeaver account by knowing the victim's email address. This can happen because QueryWeaver does not properly check if an email is already linked to an account bef...
8.8
Debian Linux: Unauthenticated Remote Code Execution
DEBIAN-CVE-2026-9323
A security issue in Debian Linux allows attackers to run malicious code without needing permission. This can happen when a user visits a compromised website or opens a malicious email attachment. To f...
8.1
urwid: Insecure Session IDs Can Be Predicted by Attackers
CVE-2026-9323
The urwid web display backend generates session IDs that can be easily predicted by attackers, allowing them to read sensitive information, inject keystrokes, and even take control of a user's session...
9.2