[vulnfeed] 29 critical CVEs — 2026-07-01 16:00 UTC
vulnfeed
Critical alert — 2026-07-01 18:21 UTC
29 new critical CVEs
in the last 5 hours — 29 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-57692CRITICAL
Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation.
This issue
Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation.
This issue affects PrivateContent: from n/a through 9.9.2.
CVSS 9.8
CVE-2026-24270CRITICAL
NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful
NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, i
CVSS 9.8
CVE-2026-57517CRITICAL
Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated r
Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input through t
CVSS 9.3
CVE-2026-58126CRITICAL
PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote at
PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP servi
CVSS 9.3
CVE-2026-58127CRITICAL
PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll,
PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirem
CVSS 9.3
CVE-2026-34099CRITICAL
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (l
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): SELECT * FROM jobs where id = '\".$_GET['id'].\"'. No authentication is required.
CVSS 9.3
CVE-2026-34100CRITICAL
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id =
CVSS 9.3
CVE-2026-34101CRITICAL
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where
CVSS 9.3
CVE-2026-34102CRITICAL
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.ph
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16): SELECT * FROM jobs where input1 = '\".$_GET['id'].\"'. An authenticated attac
CVSS 9.3
CVE-2026-34103CRITICAL
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].\"'.
CVSS 9.3
CVE-2026-34104CRITICAL
Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php
Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124): SELECT * FROM complex WHERE name='\".$_GET['name'].\"'. An authenticated attac
CVSS 9.3
CVE-2026-34105CRITICAL
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line 15): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].
CVSS 9.3
CVE-2026-34106CRITICAL
Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19
Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without sanitization: exec(\"php jobs/subtitle_rendering.php \".$login_session.\" \".$_G
CVSS 9.3
CVE-2026-34107CRITICAL
Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14
Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without sanitization: exec(\"php jobs/translate.php \".$login_session.\" \".$_GET['id'].
CVSS 9.3
CVE-2026-34108CRITICAL
Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) wit
Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanitization: exec(\"php jobs/text.php \".$login_session.\" \".$_GET['id'].\" ...\").
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: