Vulnfeed

Archives
Log in
Subscribe
August 13, 2026

[vulnfeed] 28 critical CVEs — 2026-08-13 16:00 UTC

vulnfeed Critical alert — 2026-08-13 17:25 UTC
28 new critical CVEs in the last 5 hours — 28 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-27544CRITICAL
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
CVSS 10.0
CVE-2026-61962CRITICAL
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
CVSS 10.0
CVE-2026-49827CRITICAL
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and pr
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense sc
CVSS 9.8
CVE-2026-28008CRITICAL
Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.
Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.
CVSS 9.8
CVE-2026-28148CRITICAL
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
CVSS 9.8
CVE-2026-28149CRITICAL
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
CVSS 9.8
CVE-2026-28185CRITICAL
Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
CVSS 9.8
CVE-2026-61967CRITICAL
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
CVSS 9.8
CVE-2026-66424CRITICAL
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
CVSS 9.8
CVE-2026-66453CRITICAL
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
CVSS 9.8
CVE-2026-66465CRITICAL
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
CVSS 9.8
CVE-2026-66691CRITICAL
Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
CVSS 9.8
CVE-2026-28001CRITICAL
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
CVSS 9.3
CVE-2026-28142CRITICAL
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
CVSS 9.3
CVE-2026-61966CRITICAL
Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.
Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 9 critical CVEs — 2026-08-13 20:00 UTC Older → [vulnfeed] 14 critical CVEs — 2026-08-13 12:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.