[vulnfeed] 7 critical CVEs — 2026-07-10 16:00 UTC
vulnfeed
Critical alert — 2026-07-10 18:07 UTC
7 new critical CVEs
in the last 5 hours — 7 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-55500CRITICAL
9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full databa
9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, API keys, OAuth tokens, and settings) and full data
CVSS 9.9
CVE-2026-59792CRITICAL
In JetBrains IntelliJ IDEA before 2026.1.4,
2026.2 code execution via path traversal in project workspace ID
In JetBrains IntelliJ IDEA before 2026.1.4,
2026.2 code execution via path traversal in project workspace ID handling was possible
CVSS 9.6
CVE-2026-61444CRITICAL
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can i
CVSS 9.4
CVE-2026-56765CRITICAL
Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashe
Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. The Get
CVSS 9.3
CVE-2026-15143CRITICAL
A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote
A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed wi
CVSS 9.3
CVE-2026-56261CRITICAL
Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /
Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination validation
CVSS 9.2
CVE-2026-58492CRITICAL
grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpol
grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its table argument directly into a raw SQL query string without sanitization, escapin
CVSS 9.2
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: