Vulnfeed

Archives
Log in
Subscribe
July 29, 2026

[vulnfeed] 12 critical CVEs — 2026-07-29 08:00 UTC

vulnfeed Critical alert — 2026-07-29 10:59 UTC
12 new critical CVEs in the last 5 hours — 12 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-63227CRITICAL
An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upl
An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execu
CVSS 9.9
CVE-2026-63232CRITICAL
A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to i
A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(),
CVSS 9.9
CVE-2026-63233CRITICAL
A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to i
A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed to unserialize()
CVSS 9.9
CVE-2026-63234CRITICAL
A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to i
A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed to unserialize(), w
CVSS 9.9
CVE-2025-10656CRITICAL
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter func
CVSS 9.8
CVE-2026-18191CRITICAL
VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote at
VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administrator credentials of t
CVSS 9.3
CVE-2026-58154CRITICAL
Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This
Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
CVSS 9.2
CVE-2026-58155CRITICAL
Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and polic
Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
CVSS 9.2
CVE-2026-58161CRITICAL
Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This
Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
CVSS 9.2
CVE-2026-58179CRITICAL
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This i
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, f
CVSS 9.2
CVE-2026-63229CRITICAL
A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to u
A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to read sensitive database contents,
CVSS 9.1
CVE-2026-63230CRITICAL
A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacke
A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, cred
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 12 critical CVEs — 2026-07-29 12:00 UTC Older → [vulnfeed] 1 critical CVE — 2026-07-29 04:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.