[vulnfeed] 5 critical CVEs — 2026-07-13 20:00 UTC
vulnfeed
Critical alert — 2026-07-13 21:26 UTC
5 new critical CVEs
in the last 5 hours — 5 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-61667CRITICAL
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
### Summary
The FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control t
CVSS 9.9
CVE-2026-45579CRITICAL
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
### Summary
An remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the
CVSS 9.9
CVE-2026-6875CRITICAL
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platfo
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to
CVSS 9.5
CVE-2026-61500CRITICAL
Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random(
Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during
CVSS 9.3
CVE-2026-61462CRITICAL
mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attac
mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted
CVSS 9.2
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: