Vulnfeed

Archives
Log in
Subscribe
August 22, 2026

[vulnfeed] 8 critical CVEs — 2026-08-22 00:00 UTC

vulnfeed Critical alert — 2026-08-22 01:55 UTC
8 new critical CVEs in the last 5 hours — 8 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-61539CRITICAL
Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, X
Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model
CVSS 10.0
CVE-2026-62283CRITICAL
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by
CVSS 9.9
CVE-2026-76904CRITICAL
GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and
GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when exe
CVSS 9.8
CVE-2026-77413CRITICAL
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup fun
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to a
CVSS 9.3
CVE-2026-77414CRITICAL
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty check. Crafted expressions could use $has
CVSS 9.3
CVE-2026-77415CRITICAL
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions cou
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to execute arbitrary code. The chain could ov
CVSS 9.3
CVE-2026-59989CRITICAL
Phalcon is a high-performance, full-stack PHP framework. In 5.15.0 and earlier, resolveFilter in phalcon/Mvc/V
Phalcon is a high-performance, full-stack PHP framework. In 5.15.0 and earlier, resolveFilter in phalcon/Mvc/View/Engine/Volt/Compiler.zep builds the join filter by inserting the raw separator and arr
CVSS 9.2
CVE-2026-49849CRITICAL
xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version
xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administrator to upload executable files (e.g., .php). By up
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 3 critical CVEs — 2026-08-22 12:00 UTC Older → [vulnfeed] 7 critical CVEs — 2026-08-21 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.