[vulnfeed] 24 critical CVEs — 2026-07-23 12:00 UTC
vulnfeed
Critical alert — 2026-07-23 14:39 UTC
24 new critical CVEs
in the last 5 hours — 24 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-59555CRITICAL
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
CVSS 10.0
CVE-2026-64812CRITICAL
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development ses
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
CVSS 10.0
CVE-2026-64813CRITICAL
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Developme
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
CVSS 10.0
CVE-2026-59543CRITICAL
Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
CVSS 9.9
CVE-2026-14282CRITICAL
The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more p
The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and includi
CVSS 9.8
CVE-2026-15011CRITICAL
The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'pa
The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic functi
CVSS 9.8
CVE-2026-15015CRITICAL
The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all
The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying tha
CVSS 9.8
CVE-2026-59540CRITICAL
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.
CVSS 9.8
CVE-2026-59544CRITICAL
Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
CVSS 9.8
CVE-2026-61951CRITICAL
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
CVSS 9.8
CVE-2026-57784CRITICAL
Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
CVSS 9.6
CVE-2026-65471CRITICAL
Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
CVSS 9.6
CVE-2026-65605CRITICAL
SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell re
SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escapi
CVSS 9.4
CVE-2026-65606CRITICAL
SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a s
SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an installed plugin, the applica
CVSS 9.4
CVE-2026-59514CRITICAL
Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.
Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: