Vulnfeed

Archives
Log in
Subscribe
August 2, 2026

[vulnfeed] 2 critical CVEs — 2026-08-02 12:00 UTC

vulnfeed Critical alert — 2026-08-02 14:05 UTC
2 new critical CVEs in the last 5 hours — 2 CVSS ≥ 9.0
New vulnerabilities
CVE-2025-71401CRITICAL
better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise define
better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to make the very first request to the
CVSS 9.3
CVE-2026-68582CRITICAL
Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in th
Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoi
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 3 critical CVEs — 2026-08-02 16:00 UTC Older → [vulnfeed] 1 critical CVE — 2026-08-02 04:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.