[vulnfeed] 6 critical CVEs — 2026-07-23 16:00 UTC
vulnfeed
Critical alert — 2026-07-23 17:53 UTC
6 new critical CVEs
in the last 5 hours — 6 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-65687CRITICAL
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files
CVSS 9.3
CVE-2026-65688CRITICAL
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files
CVSS 9.3
CVE-2026-65689CRITICAL
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary fil
CVSS 9.3
CVE-2026-65761CRITICAL
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improp
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, a
CVSS 9.3
CVE-2026-65760CRITICAL
Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store ext
Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and cu
CVSS 9.2
CVE-2026-65907CRITICAL
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: