[vulnfeed] 2 critical CVEs — 2026-08-06 12:00 UTC
vulnfeed
Critical alert — 2026-08-06 14:43 UTC
2 new critical CVEs
in the last 5 hours — 2 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-5134CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Sof
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection.
This issue affects CMS: t
CVSS 9.8
CVE-2026-12605CRITICAL
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admi
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin
CVSS 9.6
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: