Vulnfeed

Archives
Log in
Subscribe
July 20, 2026

[vulnfeed] 13 critical CVEs — 2026-07-20 20:00 UTC

vulnfeed Critical alert — 2026-07-20 21:38 UTC
13 new critical CVEs in the last 5 hours — 13 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-61424CRITICAL
The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.
The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.
CVSS 10.0
CVE-2026-61900CRITICAL
The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.
The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.
CVSS 10.0
CVE-2026-54051CRITICAL
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates s
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`), which THREAT_MODEL.m
CVSS 9.9
CVE-2026-35048CRITICAL
The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and wri
The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper sanitization. On PHP 8+, th
CVSS 9.8
CVE-2026-41252CRITICAL
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which all
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. The issue occurs during t
CVSS 9.8
CVE-2026-60032CRITICAL
The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executabl
The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip execute bits.
CVSS 9.4
CVE-2026-60034CRITICAL
The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served withou
The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to stored/reflected XSS.
CVSS 9.4
CVE-2026-61425CRITICAL
The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.
The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.
CVSS 9.4
CVE-2026-16337CRITICAL
Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through
Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated backend user to self-a
CVSS 9.4
CVE-2026-39878CRITICAL
Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user regis
Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in a
CVSS 9.3
CVE-2026-63766CRITICAL
GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice,
GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into sh
CVSS 9.3
CVE-2026-63767CRITICAL
ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulne
ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pic
CVSS 9.3
CVE-2026-44231CRITICAL
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and a
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerabil
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 1 critical CVE — 2026-07-21 04:00 UTC Older → [vulnfeed] 8 critical CVEs — 2026-07-20 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.