Vulnfeed

Archives
Log in
Subscribe
August 20, 2026

[vulnfeed] 21 critical CVEs — 2026-08-20 16:00 UTC

vulnfeed Critical alert — 2026-08-20 16:59 UTC
21 new critical CVEs in the last 5 hours — 21 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-73992CRITICAL
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
CVSS 9.9
CVE-2026-74014CRITICAL
Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
CVSS 9.9
CVE-2026-74016CRITICAL
Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
CVSS 9.9
CVE-2026-74018CRITICAL
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
CVSS 9.9
CVE-2025-15689CRITICAL
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
CVSS 9.8
CVE-2026-66583CRITICAL
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
CVSS 9.8
CVE-2026-66672CRITICAL
Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
CVSS 9.8
CVE-2026-66682CRITICAL
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
CVSS 9.8
CVE-2026-73993CRITICAL
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
CVSS 9.8
CVE-2026-74001CRITICAL
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
CVSS 9.8
CVE-2026-15706CRITICAL
Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade
Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass. This i
CVSS 9.8
CVE-2026-28164CRITICAL
Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request
Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7.
CVSS 9.6
CVE-2025-15688CRITICAL
Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
CVSS 9.3
CVE-2026-66592CRITICAL
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
CVSS 9.3
CVE-2026-66593CRITICAL
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 15 critical CVEs — 2026-08-20 20:00 UTC Older → [vulnfeed] 21 critical CVEs — 2026-08-20 12:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.