[vulnfeed] 27 critical CVEs — 2026-07-13 08:00 UTC
vulnfeed
Critical alert — 2026-07-13 11:34 UTC
27 new critical CVEs
in the last 5 hours — 27 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-57719CRITICAL
Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows
Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through <= 2.8.3.
CVSS 10.0
CVE-2026-57811CRITICAL
Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugi
Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusion.This issue affects Realtyn
CVSS 10.0
CVE-2026-57401CRITICAL
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm For
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDash suredash allows Path Traversal.This issue affects SureDash: from n/a through <
CVSS 9.9
CVE-2026-57710CRITICAL
Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max
Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through <= 14.1.
CVSS 9.9
CVE-2026-57724CRITICAL
Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affe
Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.
CVSS 9.8
CVE-2026-57738CRITICAL
Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This i
Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.
CVSS 9.8
CVE-2026-57744CRITICAL
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Obje
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
CVSS 9.8
CVE-2026-57770CRITICAL
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.
CVSS 9.8
CVE-2026-57813CRITICAL
Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation
Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3.
CVSS 9.8
CVE-2026-59518CRITICAL
Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This
Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.
CVSS 9.8
CVE-2026-14453CRITICAL
This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets mod
This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution. The message_confirm field is stored without sanit
CVSS 9.6
CVE-2026-22093CRITICAL
The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate
The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided by the server. This allows an attacker on the network path between the app and EV
CVSS 9.5
CVE-2026-14934CRITICAL
A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataf
A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May 10th, 2026, on Goog
CVSS 9.4
CVE-2026-4769CRITICAL
Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the init
Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible
CVSS 9.3
CVE-2026-22095CRITICAL
The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.
The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: