Vulnfeed

Archives
Log in
Subscribe
June 30, 2026

[vulnfeed] 8 critical CVEs — 2026-06-30 12:00 UTC

vulnfeed Critical alert — 2026-06-30 15:06 UTC
8 new critical CVEs in the last 5 hours — 8 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-9711CRITICAL
The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injecti
The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and including, 5.0.11 due to in
CVSS 9.8
CVE-2026-8402CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 allows Blind SQL In
CVSS 9.8
CVE-2026-44946CRITICAL
A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enfo
A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in the middle attacks aga
CVSS 9.5
CVE-2026-12076CRITICAL
Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline.  The vulnerability allows
Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline.  The vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL statements against the underl
CVSS 9.3
CVE-2026-14162CRITICAL
Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unaut
Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation.
CVSS 9.3
CVE-2026-53690CRITICAL
An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/
An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/index.php" login endpoint. The application fails to sanitize user input and directly
CVSS 9.3
CVE-2026-58116CRITICAL
LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI ac
LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to execute arbitrary Python code by supplying a malicious model path in the Chat or T
CVSS 9.3
CVE-2026-6556CRITICAL
@fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the
@fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argument is a string. Non-string mount paths (arrays of paths and regular expression
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 13 critical CVEs — 2026-06-30 16:00 UTC Older → [vulnfeed] 4 critical CVEs — 2026-06-30 08:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.