Vulnfeed

Archives
Log in
Subscribe
September 5, 2026

[vulnfeed] 4 critical CVEs — 2026-09-05 12:00 UTC

vulnfeed Critical alert — 2026-09-05 15:22 UTC
4 new critical CVEs in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-10196CRITICAL
The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vul
The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deseriali
CVSS 9.8
CVE-2026-86184CRITICAL
Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that
Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not
CVSS 9.3
CVE-2026-86189CRITICAL
WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated atta
WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avide
CVSS 9.3
CVE-2026-86190CRITICAL
WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete u
WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to un
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 2 critical CVEs — 2026-09-05 20:00 UTC Older → [vulnfeed] 2 critical CVEs — 2026-09-05 04:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.