[vulnfeed] 14 critical CVEs — 2026-08-13 12:00 UTC
vulnfeed
Critical alert — 2026-08-13 13:54 UTC
14 new critical CVEs
in the last 5 hours — 14 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-15413CRITICAL
The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an
The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detache
CVSS 10.0
CVE-2026-49827CRITICAL
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and pr
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense sc
CVSS 9.8
CVE-2026-73483CRITICAL
Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@fl
Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated user with access to the /api/v1/node-c
CVSS 9.4
CVE-2026-59506CRITICAL
CWE-306: Missing Authentication for Critical Function
CWE-306: Missing Authentication for Critical Function
CVSS 9.3
CVE-2026-59507CRITICAL
CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE
CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control
CVSS 9.3
CVE-2026-73608CRITICAL
SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched
SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched in v3.7.4) contains a missing-authorization vulnerability in the /api/av/getAttributeView
CVSS 9.2
CVE-2026-59503CRITICAL
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Info
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
CVSS 9.1
CVE-2026-59504CRITICAL
CWE-602: Client-Side Enforcement of Server-Side Security
CWE-602: Client-Side Enforcement of Server-Side Security
CVSS 9.1
CVE-2026-73485CRITICAL
Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenti
Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator bloc
CVSS 9.0
CVE-2026-73486CRITICAL
Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter t
Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbitrary Python code. The validator uses a
CVSS 9.0
CVE-2026-73487CRITICAL
Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that
Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers
CVSS 9.0
CVE-2026-73601CRITICAL
Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM
Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands
CVSS 9.0
CVE-2026-73602CRITICAL
Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authent
Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Atta
CVSS 9.0
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: