[vulnfeed] 3 critical CVEs — 2026-08-11 08:00 UTC
vulnfeed
Critical alert — 2026-08-11 09:27 UTC
3 new critical CVEs
in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-19425CRITICAL
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthen
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete dat
CVSS 9.3
CVE-2026-13716CRITICAL
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated att
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application an
CVSS 9.1
CVE-2026-19516CRITICAL
A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, an
A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: