Vulnfeed

Archives
Log in
Subscribe
July 8, 2026

[vulnfeed] 7 critical CVEs — 2026-07-08 16:00 UTC

vulnfeed Critical alert — 2026-07-08 17:55 UTC
7 new critical CVEs in the last 5 hours — 7 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-8307CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Injection. This issue affects Mediküm Web: through 080
CVSS 9.8
CVE-2026-15062CRITICAL
SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0
SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0 could allow authenticated low-privilege users to execute SQL beyond their authorization sc
CVSS 9.6
CVE-2026-58480CRITICAL
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vul
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validat
CVSS 9.2
CVE-2026-59702CRITICAL
repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauth
repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated attackers to make arbitrary outbound requests. The endpoint fails to properly va
CVSS 9.2
CVE-2026-59873CRITICAL
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard up
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction
CVSS 9.2
CVE-2026-54061CRITICAL
Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs
Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication o
CVSS 9.1
CVE-2026-9074CRITICAL
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL inject
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 2 critical CVEs — 2026-07-08 20:00 UTC Older → [vulnfeed] 3 critical CVEs — 2026-07-08 12:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.