[vulnfeed] 4 critical CVEs — 2026-09-05 12:00 UTC
vulnfeed
Critical alert — 2026-09-05 15:22 UTC
4 new critical CVEs
in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-10196CRITICAL
The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vul
The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deseriali
CVSS 9.8
CVE-2026-86184CRITICAL
Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that
Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not
CVSS 9.3
CVE-2026-86189CRITICAL
WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated atta
WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avide
CVSS 9.3
CVE-2026-86190CRITICAL
WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete u
WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to un
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: