Vulnfeed

Archives
Log in
Subscribe
August 2, 2026

[vulnfeed] 3 critical CVEs — 2026-08-02 16:00 UTC

vulnfeed Critical alert — 2026-08-02 17:29 UTC
3 new critical CVEs in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2025-71401CRITICAL
better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise define
better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to make the very first request to the
CVSS 9.3
CVE-2026-68582CRITICAL
Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in th
Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoi
CVSS 9.3
CVE-2026-65321CRITICAL
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to injec
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 4 critical CVEs — 2026-08-03 04:00 UTC Older → [vulnfeed] 2 critical CVEs — 2026-08-02 12:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.