Vulnfeed

Archives
Log in
Subscribe
July 29, 2026

[vulnfeed] 12 critical CVEs — 2026-07-29 12:00 UTC

vulnfeed Critical alert — 2026-07-29 14:37 UTC
12 new critical CVEs in the last 5 hours — 12 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-65883CRITICAL
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 2
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code executio
CVSS 10.0
CVE-2026-65884CRITICAL
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows use
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with a
CVSS 10.0
CVE-2025-10656CRITICAL
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter func
CVSS 9.8
CVE-2026-14900CRITICAL
The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up
The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function. This is due to insufficient sanitiza
CVSS 9.8
CVE-2026-65885CRITICAL
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE
CVSS 9.4
CVE-2026-9177CRITICAL
A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of th
A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This flaw allows an attacker wi
CVSS 9.4
CVE-2026-0667CRITICAL
CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code ex
CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when communicating over
CVSS 9.3
CVE-2026-58161CRITICAL
Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This
Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
CVSS 9.2
CVE-2026-58179CRITICAL
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This i
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, f
CVSS 9.2
CVE-2026-65889CRITICAL
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp me
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.
CVSS 9.2
CVE-2026-65890CRITICAL
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors all
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.
CVSS 9.2
CVE-2026-14488CRITICAL
The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatc
The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. This
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 17 critical CVEs — 2026-07-29 16:00 UTC Older → [vulnfeed] 12 critical CVEs — 2026-07-29 08:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.