[vulnfeed] 4 critical CVEs — 2026-07-13 16:00 UTC
vulnfeed
Critical alert — 2026-07-13 18:15 UTC
4 new critical CVEs
in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-45579CRITICAL
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
### Summary
An remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the
CVSS 9.9
CVE-2026-60121CRITICAL
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.ph
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a doub
CVSS 9.3
CVE-2026-61498CRITICAL
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_gra
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary command
CVSS 9.3
CVE-2026-6847CRITICAL
Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file
Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. The application exposes an endpoint that allows unauthenticated attacker
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: