[vulnfeed] 5 critical CVEs — 2026-07-31 20:00 UTC
vulnfeed
Critical alert — 2026-07-31 21:34 UTC
5 new critical CVEs
in the last 5 hours — 5 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-52887CRITICAL
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
## Summary
`GET /api/myInAppChannels:list` accepts a structured `filter` query parameter. The handler for the `latestMsgReceiveTimestamp` field splices the `$lt` value directly into a `Sequelize.lite
CVSS 10.0
CVE-2026-52855CRITICAL
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, placeholders in egg configuration-file templates allow a low-privilege
CVSS 9.9
CVE-2026-67822CRITICAL
Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoi
Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' para
CVSS 9.8
CVE-2026-54725CRITICAL
vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible.
vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.ba
CVSS 9.6
CVE-2026-58048CRITICAL
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
CVSS 9.4
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: