[vulnfeed] 37 critical CVEs — 2026-08-18 16:00 UTC
vulnfeed
Critical alert — 2026-08-18 16:55 UTC
37 new critical CVEs
in the last 5 hours — 37 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-73343CRITICAL
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
CVSS 10.0
CVE-2026-32444CRITICAL
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
CVSS 9.9
CVE-2026-32463CRITICAL
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
CVSS 9.9
CVE-2026-32474CRITICAL
Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.
Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.
CVSS 9.9
CVE-2026-66627CRITICAL
Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.
Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.
CVSS 9.9
CVE-2026-32470CRITICAL
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
CVSS 9.8
CVE-2026-59940CRITICAL
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities.
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes
CVSS 9.8
CVE-2026-73341CRITICAL
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
CVSS 9.8
CVE-2026-73366CRITICAL
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
CVSS 9.8
CVE-2026-73376CRITICAL
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
CVSS 9.8
CVE-2026-73380CRITICAL
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
CVSS 9.8
CVE-2026-73397CRITICAL
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
CVSS 9.8
CVE-2026-73996CRITICAL
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
CVSS 9.8
CVE-2026-45117CRITICAL
MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly
MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configuration values written to the configuration file, resu
CVSS 9.8
CVE-2026-28192CRITICAL
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
CVSS 9.6
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: