Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 20 July 2026

RSS

621 vulnerabilities published on 20 July 2026

Severity:
Joomla JDownloads allows unauthenticated file upload
CVE-2026-61900
The JDownloads extension for Joomla websites allows hackers to upload any file without a password. This means they can install malware or take full control of the website. To stay safe, update the JDo...
10.0
DJ-Classifieds Joomla Extension Allows Unauthenticated File Upload
CVE-2026-61424
The DJ-Classifieds Joomla extension has a security flaw that allows anyone to upload files without a password. This means an attacker can potentially take control of the website and execute any malici...
10.0
Malicious Code in @beproduct/nestjs-auth (0.1.2-0.1.19) Can Steal Secrets
GHSA-6xwp-cp5h-q856 CVE-2026-46412
Between May 11 and May 22, 2026, malicious versions of the @beproduct/nestjs-auth package were published on npm. These versions contained code that could steal sensitive information like login tokens,...
10.0
Network-AI: Malicious Commands Can Be Executed Through Wildcard Allowlists
GHSA-qw6v-5fcf-5666 CVE-2026-54051
A security issue in Network-AI allows malicious commands to be executed if they match a wildcard allowlist. This could allow an attacker to run arbitrary code on a compromised agent. To fix this, ensu...
9.9
FileThingie v2.5.7 Leaks Sensitive Information
CVE-2026-51027
A vulnerability in FileThingie v2.5.7 allows a hacker to access sensitive information without permission. This is a serious security risk because it could expose confidential data. To protect your dat...
9.9
AVideo < 29.0: Attackers can run arbitrary system commands
CVE-2026-64625
AVideo versions before 29.0 have a security flaw that allows hackers to execute malicious system commands. This could lead to unauthorized access or data theft. Update to version 29.0 or later to fix ...
9.3
ktransformers Unauthenticated Command Execution via Pickle Payload
CVE-2026-63767
The ktransformers library, up to version 0.6.3, can be exploited by attackers to execute arbitrary commands on a server. This can happen when a malicious pickle payload is sent to the server, potentia...
9.3
GPT-SoVITS through 20250606v2pro: Unsecured OS Command Execution
CVE-2026-63766
GPT-SoVITS, a text-to-image model, is at risk if attackers can inject malicious commands through its web interface. This could allow unauthorized access to the system and potentially lead to data thef...
9.3
xrdp: Unvalidated Color Index Can Cause Remote Code Execution
CVE-2026-41252
Versions of xrdp prior to 0.10.6 contain a security flaw that can be exploited by a malicious VNC server to execute unauthorized code on a remote system. This can happen before the user even logs in, ...
9.8
Piwigo Installer Allows Arbitrary PHP Code Injection
CVE-2026-35048
Piwigo installers in versions 16.3.0 and earlier are vulnerable to code injection attacks. This means an attacker can inject malicious code into your website by sending special data to the installer. ...
9.8
FreeRDP before 3.28.0 allows unauthorized denial of service
CVE-2026-64620
FreeRDP versions 3.27.1 and earlier are vulnerable to a denial of service attack. An attacker can send a specially crafted message to the server, causing it to run out of memory. To protect your syste...
9.3
rootio-imagemagick: Malicious Image Processing
ROOT-OS-DEBIAN-13-CVE-2023-34152
A security patch has been released for the rootio-imagemagick package, which is used to process images on Root systems. This patch fixes a vulnerability that could allow attackers to execute malicious...
9.8
Perl Crypt::Password versions through 0.28 may leak password data
CVE-2026-16235
Perl's Crypt::Password versions 0 through 0.28 may expose passwords due to the use of a predictable random number generator. This is particularly concerning for password storage and authentication sys...
9.8
FreeScout: Unauthenticated takeover of lowest-id user account
CVE-2026-53595
FreeScout, a free help desk and shared inbox, has a security flaw that allows an attacker to take over the account of the lowest-id user, potentially an administrator, without needing a password. This...
9.4
dotCMS: Low-Privileged User Can Gain Admin Access
CVE-2026-16337
A low-privileged user can gain admin access to dotCMS and potentially execute arbitrary shell commands. This affects dotCMS versions 21.02 through 26.06.22-03 on all platforms. To fix, update to a pat...
9.4
Joomla JMedia Extension: Unsecured SVG Uploads Cause Harmful Code Injection
CVE-2026-60034
The JMedia extension for Joomla allows attackers to inject malicious code into websites through unsanitised SVG uploads. This can happen when a user with administrative access uploads a malicious SVG ...
9.4
Joomla JMedia Extension Allows Malicious File Uploads
CVE-2026-60032
The JMedia extension in Joomla allows authorized users to upload any type of file, potentially allowing attackers to execute malicious code on the server. This is a serious issue because it can lead t...
9.4
Joomla Gridbox Extension - Unauthenticated Admin Access
CVE-2026-61425
The Gridbox extension in Joomla versions before 1.6.0 has a security flaw that could allow an attacker to access the admin area without logging in. This means that sensitive data and settings could be...
9.4
Hypershift Konnectivity Proxy Allows Unauthenticated Agent Connections
CVE-2026-16242
The Konnectivity proxy-server in Hypershift does not verify the identity of agents connecting to it. This means an attacker who can reach the proxy could connect without being authenticated, and poten...
9.4
LightRAG: Unauthenticated API Key Bypass via Guest Token
CVE-2026-61740 GHSA-f4vv-55c2-5789
A security flaw in LightRAG versions prior to 1.5.4 allows an attacker to access sensitive data and perform actions without authentication. This is fixed in version 1.5.4, so update to the latest vers...
9.3
LightRAG: Malicious Websites Can Steal or Delete Data
CVE-2026-61736 GHSA-6x6h-qqr7-855w
A security issue in LightRAG allows malicious websites to make requests to LightRAG's API on behalf of authenticated users, potentially stealing or deleting sensitive data. This can happen when a user...
9.3
Chamilo LMS versions 1.11.38 and earlier allow attackers to take control of admin accounts.
CVE-2026-39878
Chamilo Learning Management System versions 1.11.38 and earlier have a security flaw in the user registration form. This means an attacker can trick an administrator into running malicious code in the...
9.3
Windu CMS SQL Injection in URL Path
CVE-2026-57309
Windu CMS versions, including 4.1, are at risk of SQL injection attacks. An attacker can inject malicious SQL code into the URL, potentially stealing sensitive data or disrupting the website. Update t...
9.3
RT Issue Tracker: Privileged User Can Steal Admin Credentials
CVE-2026-44231
RT's issue and ticket tracking system has a security flaw that allows a non-admin user to steal admin passwords and use them to access sensitive data. This happens when a user requests a specific type...
9.1
Pillow HEIF Library: Integer Overflow in Image Processing
CVE-2026-28231 GHSA-5gjj-6r7v-ph3x
A security issue in the Pillow HEIF library can cause a program to crash or leak sensitive information when processing large images. This issue affects versions of the library before 1.3.0. To fix the...
7.8