Vulnfeed

Archives
Log in
Subscribe
July 21, 2026

[vulnfeed] 14 critical CVEs — 2026-07-21 20:00 UTC

vulnfeed Critical alert — 2026-07-21 21:37 UTC
14 new critical CVEs in the last 5 hours — 14 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-47410CRITICAL
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 h
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcode
CVSS 9.8
CVE-2026-20896CRITICAL
Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X
# Summary The Gitea Docker images ship an `app.ini` template that hard-codes:
REVERSE_PROXY_TRUSTED_PROXIES = *
The documented default for this setting, in `custom/conf/app.example.ini`, is
CVSS 9.8
CVE-2026-47413CRITICAL
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 h
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST /workspaces/{workspac
CVSS 9.6
CVE-2026-47416CRITICAL
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 a
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/memb
CVSS 9.6
CVE-2026-58443CRITICAL
Gitea: Public-only repository tokens can update private PR head branches
### Summary Gitea allows a `public-only,write:repository` token to update a private pull request head branch through a public base repository route. The vulnerable endpoint is: ```text POST /api/v1/
CVSS 9.6
CVE-2026-58426CRITICAL
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task uplo
### Summary Gitea Actions Artifacts V4 signed upload/download URLs can be rewritten to access a different running task and repository context while preserving the original HMAC signature. An attacker
CVSS 9.6
CVE-2026-22874CRITICAL
Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter
## Summary Gitea's default SSRF allow-list ([`MatchBuiltinExternal`](https://github.com/go-gitea/gitea/blob/4c37f4dacbac022f7beca75272439331f0368830/modules/hostmatcher/hostmatcher.go#L26-L27), used
CVSS 9.6
CVE-2026-59891CRITICAL
Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
### Impact This is a credential-exposure / credential-confusion issue. `getRegistryCredentials()` reads credentials from the Docker config file (`~/.docker/config.json`) and selects an entry by chec
CVSS 9.6
CVE-2026-47407CRITICAL
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, t
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources under `/api/v1/workspaces/{workspace_id}/...` and pro
CVSS 9.4
CVE-2026-64877CRITICAL
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.
CVSS 9.4
CVE-2026-64878CRITICAL
Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling,
Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpo
CVSS 9.4
CVE-2026-64879CRITICAL
A filename supplied during file upload is not properly sanitized before being used in system command execution
A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via th
CVSS 9.4
GHSA-p63j-vcc4-9vmvCRITICAL
@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
## Summary Browser Mode exposes a set of built-in "commands" that run on the Node.js side of the test runner and can touch the local filesystem (taking screenshots, managing Playwright traces, upload
CVSS 9.4
CVE-2016-20096CRITICAL
Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability tha
Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name param
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 1 critical CVE — 2026-07-22 12:00 UTC Older → [vulnfeed] 23 critical CVEs — 2026-07-21 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.