Vulnfeed

Archives
Log in
Subscribe
August 19, 2026

[vulnfeed] 34 critical CVEs — 2026-08-19 16:00 UTC

vulnfeed Critical alert — 2026-08-19 16:53 UTC
34 new critical CVEs in the last 5 hours — 34 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-67364CRITICAL
Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CV
Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP
CVSS 10.0
CVE-2026-74803CRITICAL
Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element ac
Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME gr
CVSS 10.0
CVE-2026-75949CRITICAL
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory <
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the co
CVSS 10.0
CVE-2026-15068CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbit
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVSS 9.9
CVE-2026-16816CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVSS 9.9
CVE-2026-66613CRITICAL
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
CVSS 9.8
CVE-2026-73347CRITICAL
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.
CVSS 9.8
CVE-2026-73364CRITICAL
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
CVSS 9.8
CVE-2026-73389CRITICAL
Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
CVSS 9.8
CVE-2026-73390CRITICAL
Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.
Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.
CVSS 9.8
CVE-2026-16019CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam I
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows SQL Injection. This issue affects FAYDAM Datalogg
CVSS 9.8
CVE-2026-16656CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to imp
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication.
CVSS 9.8
CVE-2026-52889CRITICAL
Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field
Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer URL, Current URL, Current URL without Query Str
CVSS 9.8
CVE-2026-53451CRITICAL
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO
CVSS 9.8
CVE-2026-45272CRITICAL
MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook. In 3.41.2
MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post handler in webserver/handlers/admin.py accepts SOCIAL_
CVSS 9.4

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 52 critical CVEs — 2026-08-19 20:00 UTC Older → [vulnfeed] 2 critical CVEs — 2026-08-19 04:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.