Vulnfeed

Archives
Log in
Subscribe
July 20, 2026

[vulnfeed] 8 critical CVEs — 2026-07-20 16:00 UTC

vulnfeed Critical alert — 2026-07-20 18:26 UTC
8 new critical CVEs in the last 5 hours — 8 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-46412CRITICAL
@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Conne
@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm
CVSS 10.0
CVE-2026-51027CRITICAL
An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php compo
An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.
CVSS 9.9
CVE-2026-54051CRITICAL
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates s
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`), which THREAT_MODEL.m
CVSS 9.9
CVE-2026-35048CRITICAL
The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and wri
The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper sanitization. On PHP 8+, th
CVSS 9.8
CVE-2026-41252CRITICAL
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which all
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. The issue occurs during t
CVSS 9.8
CVE-2026-46428CRITICAL
lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-bo
lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's `boring-tls` integration silently disables TLS hostname verification
CVSS 9.1
CVE-2026-12701CRITICAL
A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that
A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such
CVSS 9.0
CVE-2026-35198CRITICAL
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulne
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaS
CVSS 9.0

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 13 critical CVEs — 2026-07-20 20:00 UTC Older → [vulnfeed] 5 critical CVEs — 2026-07-20 12:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.