[vulnfeed] 12 critical CVEs — 2026-07-29 08:00 UTC
vulnfeed
Critical alert — 2026-07-29 10:59 UTC
12 new critical CVEs
in the last 5 hours — 12 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-63227CRITICAL
An unrestricted SCORM file upload vulnerability
in Koollab LMS allowed
an authenticated module designer to upl
An unrestricted SCORM file upload vulnerability
in Koollab LMS allowed
an authenticated module designer to upload a SCORM package containing a PHP
webshell to a publicly accessible directory and execu
CVSS 9.9
CVE-2026-63232CRITICAL
A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to i
A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment
reinforcement endpoint, control data passed to unserialize(),
CVSS 9.9
CVE-2026-63233CRITICAL
A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to i
A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment
overall answer endpoint, control data passed to unserialize()
CVSS 9.9
CVE-2026-63234CRITICAL
A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to i
A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark
assessment endpoint, control data passed to unserialize(), w
CVSS 9.9
CVE-2025-10656CRITICAL
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter func
CVSS 9.8
CVE-2026-18191CRITICAL
VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote at
VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administrator credentials of t
CVSS 9.3
CVE-2026-58154CRITICAL
Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers.
This
Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
CVSS 9.2
CVE-2026-58155CRITICAL
Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and polic
Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
CVSS 9.2
CVE-2026-58161CRITICAL
Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling.
This
Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
CVSS 9.2
CVE-2026-58179CRITICAL
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input.
This i
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, f
CVSS 9.2
CVE-2026-63229CRITICAL
A pre-authentication blind SQL injection
vulnerability in Koollab LMS allowed an unauthenticated attacker to u
A pre-authentication blind SQL injection
vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via
the SSO OAuth endpoint to read sensitive database contents,
CVSS 9.1
CVE-2026-63230CRITICAL
A pre-authentication error-based SQL injection
vulnerability in Koollab LMS allowed an unauthenticated attacke
A pre-authentication error-based SQL injection
vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database
contents, including personally identifiable information, cred
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: