VulnSea

Daily digest

Sunday 14 June 2026

A quiet day: only 7 new CVEs against a recent average of about 79. Of those, 3 high.

7
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 7 that matter most of the 7 published.

CVE-2026-54410High· 8.6
3mo ago

nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte re…

nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte re…

▾ TwilightEPSS 0.86%via NVD
CVE-2026-54413High· 8.2
3mo ago

driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potential…

driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potential…

▾ TwilightEPSS 0.72%via NVD
CVE-2026-54412High· 8.2
3mo ago

LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - …

LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - …

▾ TwilightEPSS 0.72%via NVD
CVE-2026-54421Medium· 6.8
3mo ago

OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties

OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties

▾ Sunlitironic · ironicEPSS 0.47%via OSV
CVE-2026-54411Medium· 5.9
3mo ago

Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeate…

Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeate…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.50%via NVD
CVE-2025-15546Medium· 5.4
3mo ago

The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the fi…

The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the fi…

▾ SunlitEPSS 0.16%via NVD
MAL-2026-5768None
3mo ago

Malicious code in bash8 (PyPI)

Malicious code in bash8 (PyPI)

▾ Sunlitbash8 · bash8via OSV

Most-affected vendors

By CVEs published in the period.