Vulnfeed

Archives
Log in
Subscribe
August 11, 2026

[vulnfeed] 3 critical CVEs — 2026-08-11 08:00 UTC

vulnfeed Critical alert — 2026-08-11 09:27 UTC
3 new critical CVEs in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-19425CRITICAL
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthen
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete dat
CVSS 9.3
CVE-2026-13716CRITICAL
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated att
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application an
CVSS 9.1
CVE-2026-19516CRITICAL
A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, an
A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 7 critical CVEs — 2026-08-11 12:00 UTC Older → [vulnfeed] 2 critical CVEs — 2026-08-11 04:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.