Vulnfeed

Archives
Log in
Subscribe
June 30, 2026

[vulnfeed] 4 critical CVEs — 2026-06-30 08:00 UTC

vulnfeed Critical alert — 2026-06-30 11:24 UTC
4 new critical CVEs in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-9711CRITICAL
The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injecti
The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and including, 5.0.11 due to in
CVSS 9.8
CVE-2026-12818CRITICAL
Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or thrott
Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-770) within their Modbus TCP service.
CVSS 9.3
CVE-2026-12819CRITICAL
Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or acc
Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access control, permitting unauthenticated interaction with security-sensitive PLC functions.
CVSS 9.3
CVE-2026-12076CRITICAL
Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline.  The vulnerability allows
Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline.  The vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL statements against the underl
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 8 critical CVEs — 2026-06-30 12:00 UTC Older → [vulnfeed] 4 critical CVEs — 2026-06-29 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.