Vulnfeed

Archives
Log in
Subscribe
July 1, 2026

[vulnfeed] 24 critical CVEs — 2026-07-01 20:00 UTC

vulnfeed Critical alert — 2026-07-01 21:57 UTC
24 new critical CVEs in the last 5 hours — 24 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-50160CRITICAL
Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026
Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated POST /v1/onboarding/config endpoint is vulnerable to
CVSS 10.0
CVE-2026-44935CRITICAL
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm
### Impact A vulnerability in Fleet for Rancher Manager affects multi-tenancy environments where different tenants share the same downstream clusters (e.g., different privileged or untrusted teams ins
CVSS 9.9
CVE-2026-44939CRITICAL
Rancher vulnerable to command injection through unsanitized YAML parameter
### Impact A critical command injection vulnerability has been identified in the Rancher Manager cluster import endpoint `/v3/import/{token}_{clusterId}.yaml` through unsanitized YAML parameters. Thi
CVSS 9.6
CVE-2026-34099CRITICAL
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (l
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): SELECT * FROM jobs where id = '\".$_GET['id'].\"'. No authentication is required.
CVSS 9.3
CVE-2026-34100CRITICAL
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id =
CVSS 9.3
CVE-2026-34101CRITICAL
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where
CVSS 9.3
CVE-2026-34102CRITICAL
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.ph
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16): SELECT * FROM jobs where input1 = '\".$_GET['id'].\"'. An authenticated attac
CVSS 9.3
CVE-2026-34103CRITICAL
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].\"'.
CVSS 9.3
CVE-2026-34104CRITICAL
Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php
Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124): SELECT * FROM complex WHERE name='\".$_GET['name'].\"'. An authenticated attac
CVSS 9.3
CVE-2026-34105CRITICAL
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line 15): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].
CVSS 9.3
CVE-2026-34106CRITICAL
Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19
Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without sanitization: exec(\"php jobs/subtitle_rendering.php \".$login_session.\" \".$_G
CVSS 9.3
CVE-2026-34107CRITICAL
Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14
Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without sanitization: exec(\"php jobs/translate.php \".$login_session.\" \".$_GET['id'].
CVSS 9.3
CVE-2026-34108CRITICAL
Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) wit
Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanitization: exec(\"php jobs/text.php \".$login_session.\" \".$_GET['id'].\" ...\").
CVSS 9.3
CVE-2026-34109CRITICAL
Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) w
Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) without sanitization: exec(\"php jobs/speech_audio.php \".$login_session.\" \".$_GET['id'].
CVSS 9.3
CVE-2026-34110CRITICAL
Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (lin
Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) without sanitization: exec(\"php jobs/complex.php \".$login_session.\" \".$_GET['id'
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 15 critical CVEs — 2026-07-02 16:00 UTC Older → [vulnfeed] 29 critical CVEs — 2026-07-01 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.