Vulnfeed

Archives
Log in
Subscribe
August 14, 2026

[vulnfeed] 8 critical CVEs — 2026-08-14 12:00 UTC

vulnfeed Critical alert — 2026-08-14 13:50 UTC
8 new critical CVEs in the last 5 hours — 8 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-72811CRITICAL
SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/m
SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor te
CVSS 9.9
CVE-2026-72822CRITICAL
The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope
The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa auth
CVSS 9.3
CVE-2026-72824CRITICAL
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesContr
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-toggle check uses a bare isSuperAdmin() gate that does
CVSS 9.3
CVE-2026-72826CRITICAL
The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key
The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey. The self-target path of requireApiKey
CVSS 9.3
CVE-2026-72829CRITICAL
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersContr
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. These methods enforce the scope cap only for api.us
CVSS 9.3
CVE-2026-72830CRITICAL
Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gate
Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with a scoped api.conf
CVSS 9.3
CVE-2026-72810CRITICAL
SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions
SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a WebSo
CVSS 9.2
CVE-2026-72836CRITICAL
FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory owne
FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser'
CVSS 9.2

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 1 critical CVE — 2026-08-14 16:00 UTC Older → [vulnfeed] 1 critical CVE — 2026-08-14 08:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.