[vulnfeed] 11 critical CVEs — 2026-07-10 20:00 UTC
vulnfeed
Critical alert — 2026-07-10 21:32 UTC
11 new critical CVEs
in the last 5 hours — 11 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-50551CRITICAL
SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
SiYuan v3.6.5 and earlier versions contain a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset cell renderer that escalates to remote code execution (RCE) in the E
CVSS 9.9
CVE-2026-54158CRITICAL
SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
### Summary
The attribute-view (database) cell renderer `genAVValueHTML` interpolates cell content raw in four of its branches: `text`, `url`, `phone`, and `mAsset`. A cell value like `</textarea><im
CVSS 9.9
CVE-2026-54067CRITICAL
SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
### Summary
A CSS snippet body containing `</style>` breaks out of its surrounding `<style>` tag when `renderSnippet()` interpolates it via `insertAdjacentHTML`. A payload like `</style><img src=x on
CVSS 9.9
CVE-2026-2397CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Ret
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows SQL Injection.
This issue affects MobilMen 20T: f
CVSS 9.8
CVE-2026-5801CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek I
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP allows Command Line Execution throug
CVSS 9.8
CVE-2026-59151CRITICAL
Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email do
Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant should receive the final token,
CVSS 9.6
CVE-2026-61459CRITICAL
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_g
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerou
CVSS 9.3
CVE-2026-54072CRITICAL
Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL
## Summary
The `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` or `response_type=id_token`, the server appends `access_toke
CVSS 9.3
CVE-2026-58492CRITICAL
grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpol
grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its table argument directly into a raw SQL query string without sanitization, escapin
CVSS 9.2
CVE-2026-51119CRITICAL
An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/Create
An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser components
CVSS 9.1
CVE-2026-54089CRITICAL
File Browser: Authentication Bypass via Proxy Auth Header Forgery
## Summary
When FileBrowser is configured with proxy authentication (`auth.method=proxy`), any unauthenticated attacker who can reach the server directly can impersonate **any user - including admin*
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: