Daily digest
Saturday 20 June 2026
A quiet day: only 11 new CVEs against a recent average of about 109. Of those, 2 critical and 3 high. One arrived with exploitation evidence or public exploit code already attached. vllm was the most-affected vendor with 3.
New this day, ranked by depth score
The 11 that matter most of the 11 published.
CVE-2026-48939Critical· 9.8CISA KEVPoCA vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
GHSA-5w6g-rc45-wvv9Critical· 9.8Duplicate Advisory: Flowise OverrideConfig security vulnerability
Duplicate Advisory: Flowise OverrideConfig security vulnerability
CVE-2026-56340High· 8.8vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing
vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default, an attacker can submit crafted embedding requests with mal…
GHSA-78fp-cf4h-g36pHigh· 8.8Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164
Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164
GHSA-rg7q-4223-phjwHigh· 7.5Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
GHSA-xj9w-cgqg-q897Medium· 6.5Duplicate Advisory: AVideo has Unauthenticated PGP Message Decryption via Public Endpoint
Duplicate Advisory: AVideo has Unauthenticated PGP Message Decryption via Public Endpoint
GHSA-vfm7-4h43-gp6mMedium· 4.3Duplicate Advisory: vLLM Vulnerable to Regular Expression Denial of Service
Duplicate Advisory: vLLM Vulnerable to Regular Expression Denial of Service
GHSA-xppm-jmw6-fhmfLowDuplicate Advisory: Cross-site scripting via <NoScript> slot content in Nuxt's head components
Duplicate Advisory: Cross-site scripting via <NoScript> slot content in Nuxt's head components
MAL-2026-6246NoneMalicious code in d0rk3r (PyPI)
Malicious code in d0rk3r (PyPI)
MAL-2026-6245NoneMalicious code in request-cache-py (PyPI)
Malicious code in request-cache-py (PyPI)
MAL-2026-6236NoneMalicious code in query-profile (PyPI)
Malicious code in query-profile (PyPI)
Most-affected vendors
By CVEs published in the period.