[vulnfeed] 5 critical CVEs — 2026-07-09 08:00 UTC
vulnfeed
Critical alert — 2026-07-09 11:28 UTC
5 new critical CVEs
in the last 5 hours — 5 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-14245CRITICAL
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authenticat
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including,
CVSS 9.8
CVE-2026-15158CRITICAL
The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and i
The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extens
CVSS 9.8
CVE-2026-5955CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove S
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection.
This issue affects BiEtica
CVSS 9.8
CVE-2026-47840CRITICAL
A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certi
A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user passwor
CVSS 9.3
CVE-2026-2342CRITICAL
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicS
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS.
This issue affects ValeApp: throu
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: