Vulnfeed

Archives
Log in
Subscribe
July 23, 2026

[vulnfeed] 10 critical CVEs — 2026-07-23 20:00 UTC

vulnfeed Critical alert — 2026-07-23 21:32 UTC
10 new critical CVEs in the last 5 hours — 10 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-47668CRITICAL
DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /ru
DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parame
CVSS 10.0
CVE-2026-6516CRITICAL
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
CVSS 10.0
CVE-2026-47752CRITICAL
Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulne
Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification template feature. The `
CVSS 9.9
CVE-2026-47670CRITICAL
DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Cod
DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS command
CVSS 9.4
CVE-2026-65761CRITICAL
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improp
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, a
CVSS 9.3
CVE-2026-65700CRITICAL
h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows un
h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to th
CVSS 9.3
CVE-2026-65701CRITICAL
SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the ful
SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrat
CVSS 9.3
CVE-2026-47669CRITICAL
DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `pa
DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file pa
CVSS 9.3
CVE-2026-63359CRITICAL
The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthent
The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other
CVSS 9.3
CVE-2026-65760CRITICAL
Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store ext
Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and cu
CVSS 9.2

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 9 critical CVEs — 2026-07-24 00:00 UTC Older → [vulnfeed] 6 critical CVEs — 2026-07-23 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.