[vulnfeed] 5 critical CVEs — 2026-07-31 04:00 UTC
vulnfeed
Critical alert — 2026-07-31 07:20 UTC
5 new critical CVEs
in the last 5 hours — 5 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-63223CRITICAL
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rule
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacke
CVSS 9.8
CVE-2026-63221CRITICAL
CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitut
CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape fla
CVSS 9.4
CVE-2026-43829CRITICAL
Successful
exploitation of the vulnerability could allow an unauthenticated attacker to
exploit a stack-based
Successful
exploitation of the vulnerability could allow an unauthenticated attacker to
exploit a stack-based buffer overflow in the password functionality to conduct
code execution when the SafeEnhan
CVSS 9.2
CVE-2026-43831CRITICAL
Successful
exploitation of the vulnerability could allow an unauthenticated attacker to
exploit a stack-based
Successful
exploitation of the vulnerability could allow an unauthenticated attacker to
exploit a stack-based buffer overflow in the log message functionality to
conduct code execution.
CVSS 9.2
CVE-2026-43832CRITICAL
Successful exploitation of the
vulnerability could allow an unauthenticated attacker to exploit a stack-based
Successful exploitation of the
vulnerability could allow an unauthenticated attacker to exploit a stack-based
buffer overflow in the Cookie parsing methods to conduct code execution when
the SafeEnhan
CVSS 9.2
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: