Vulnfeed

Archives
Log in
Subscribe
July 8, 2026

[vulnfeed] 3 critical CVEs — 2026-07-08 12:00 UTC

vulnfeed Critical alert — 2026-07-08 14:45 UTC
3 new critical CVEs in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-8307CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Injection. This issue affects Mediküm Web: through 080
CVSS 9.8
CVE-2026-58480CRITICAL
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vul
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validat
CVSS 9.2
CVE-2026-54061CRITICAL
Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs
Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication o
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 7 critical CVEs — 2026-07-08 16:00 UTC Older → [vulnfeed] 3 critical CVEs — 2026-07-08 08:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.