[vulnfeed] 5 critical CVEs — 2026-08-04 08:00 UTC
vulnfeed
Critical alert — 2026-08-04 11:00 UTC
5 new critical CVEs
in the last 5 hours — 5 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-14175CRITICAL
Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy In
Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server.
This issue
CVSS 9.8
CVE-2026-15721CRITICAL
Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HU
Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection.
This issue affects HUMANIST Digital
CVSS 9.8
CVE-2026-18753CRITICAL
The
product firmware contains an embedded, static RSA private key utilized by the
Lighttpd web server for TLS
The
product firmware contains an embedded, static RSA private key utilized by the
Lighttpd web server for TLS termination. Exposure of this private key allows
malicious actors to breach the confidenti
CVSS 9.1
CVE-2026-18754CRITICAL
The
product firmware contains an embedded, static RSA private key utilized by the
Lighttpd web server for TLS
The
product firmware contains an embedded, static RSA private key utilized by the
Lighttpd web server for TLS termination. Exposure of this private key allows
malicious actors to breach the confidenti
CVSS 9.1
CVE-2026-14804CRITICAL
Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST
Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable.
This issue
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: