[vulnfeed] 6 critical CVEs — 2026-08-03 20:00 UTC
vulnfeed
Critical alert — 2026-08-03 21:36 UTC
6 new critical CVEs
in the last 5 hours — 6 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-38447CRITICAL
osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, comb
osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, signific
CVSS 9.8
CVE-2026-69240CRITICAL
Sequelize: SQL Injection (Oracle DB)
### Summary
SQL Injection is possible with strings only **if dialect is set to `oracle`**.
The vulnerability was confirmed on Sequelize v6.37.3.
### Details
The `escape` function defined in `sql-stri
CVSS 9.8
CVE-2026-39932CRITICAL
OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (
OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitr
CVSS 9.4
CVE-2026-41452CRITICAL
Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unaut
Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a cr
CVSS 9.3
CVE-2026-48031CRITICAL
go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions pr
go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known string "random", letti
CVSS 9.1
CVE-2026-67598CRITICAL
Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.ph
Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configure
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: