[vulnfeed] 12 critical CVEs — 2026-07-30 20:00 UTC
vulnfeed
Critical alert — 2026-07-30 21:38 UTC
12 new critical CVEs
in the last 5 hours — 12 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-13435CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sa
IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.
CVSS 9.9
CVE-2026-12946CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, du
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.
CVSS 9.9
CVE-2026-12940CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment
IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability
CVSS 9.8
CVE-2026-51291CRITICAL
sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert function of the JSON cache managemen
sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert function of the JSON cache management module.
CVSS 9.8
CVE-2026-12118CRITICAL
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute ar
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
CVSS 9.8
CVE-2026-12943CRITICAL
IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IB
IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arb
CVSS 9.8
CVE-2026-51272CRITICAL
In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the latinToUTF8() c
In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the latinToUTF8() character encoding conversion function. The function calculates required buffer size by sim
CVSS 9.8
CVE-2026-66066CRITICAL
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untruste
CVSS 9.5
CVE-2026-48499CRITICAL
Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment i
Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an authenticated flow author reach read-write cached flow
CVSS 9.3
CVE-2026-67208CRITICAL
Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attacke
Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console u
CVSS 9.3
CVE-2026-67594CRITICAL
Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated re
Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware,
CVSS 9.3
CVE-2026-51290CRITICAL
SQLite 3.41 has a use-after-free vulnerability in the shared cache lock management logic of the btree module.
SQLite 3.41 has a use-after-free vulnerability in the shared cache lock management logic of the btree module. The program frees a BtLock structure without removing the node from the linked list. Subse
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: