Vulnfeed

Archives
Log in
Subscribe
August 16, 2026

[vulnfeed] 5 critical CVEs — 2026-08-16 16:00 UTC

vulnfeed Critical alert — 2026-08-16 16:47 UTC
5 new critical CVEs in the last 5 hours — 5 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-74251CRITICAL
Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 -
Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public sh
CVSS 9.3
CVE-2026-73056CRITICAL
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulne
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Tok
CVSS 9.3
CVE-2026-73061CRITICAL
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows templ
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can mo
CVSS 9.3
CVE-2026-74790CRITICAL
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowin
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can
CVSS 9.3
CVE-2026-74791CRITICAL
Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, all
Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-de
CVSS 9.2

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 1 critical CVE — 2026-08-17 04:00 UTC Older → [vulnfeed] 1 critical CVE — 2026-08-16 12:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.