Vulnfeed

Archives
Log in
Subscribe
July 17, 2026

[vulnfeed] 4 critical CVEs — 2026-07-17 04:00 UTC

vulnfeed Critical alert — 2026-07-17 06:34 UTC
4 new critical CVEs in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-14956CRITICAL
The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin
The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds parameter in the Pro Forms
CVSS 9.8
CVE-2026-15982CRITICAL
The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is v
The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is due
CVSS 9.8
CVE-2026-62241CRITICAL
clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-c
clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/sca
CVSS 9.3
CVE-2026-62232CRITICAL
Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the rege
Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authorization, during the pending TOT
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 1 critical CVE — 2026-07-17 08:00 UTC Older → [vulnfeed] 5 critical CVEs — 2026-07-17 00:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.