Vulnfeed

Archives
Log in
Subscribe
August 7, 2026

[vulnfeed] 3 critical CVEs — 2026-08-07 16:00 UTC

vulnfeed Critical alert — 2026-08-07 17:13 UTC
3 new critical CVEs in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2022-4995CRITICAL
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote,
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submittin
CVSS 9.3
CVE-2026-19264CRITICAL
Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-su
Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising th
CVSS 9.3
CVE-2026-66914CRITICAL
Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unaut
Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download files from both inside and outside the webroot.
CVSS 9.2

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 4 critical CVEs — 2026-08-07 20:00 UTC Older → [vulnfeed] 5 critical CVEs — 2026-08-07 12:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.