[vulnfeed] 3 critical CVEs — 2026-08-02 16:00 UTC
vulnfeed
Critical alert — 2026-08-02 17:29 UTC
3 new critical CVEs
in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2025-71401CRITICAL
better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise define
better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to make the very first request to the
CVSS 9.3
CVE-2026-68582CRITICAL
Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in th
Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoi
CVSS 9.3
CVE-2026-65321CRITICAL
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to injec
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: