VulnSea

Daily digest

Saturday 20 June 2026

A quiet day: only 11 new CVEs against a recent average of about 109. Of those, 2 critical and 3 high. One arrived with exploitation evidence or public exploit code already attached. vllm was the most-affected vendor with 3.

11
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 11 that matter most of the 11 published.

CVE-2026-48939Critical· 9.8CISA KEVPoC
3mo ago

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

▾ Hadaljoomlic · icagendaEPSS 20%via NVD
GHSA-5w6g-rc45-wvv9Critical· 9.8
3mo ago

Duplicate Advisory: Flowise OverrideConfig security vulnerability

Duplicate Advisory: Flowise OverrideConfig security vulnerability

▾ Midnightflowise · flowisevia GHSA
CVE-2026-56340High· 8.8
3mo ago

vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing

vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default, an attacker can submit crafted embedding requests with mal…

▾ Twilightvllm · vllmEPSS 0.64%via NVD
GHSA-78fp-cf4h-g36pHigh· 8.8
3mo ago

Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164

Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164

▾ Twilightvllm · vllmvia GHSA
GHSA-rg7q-4223-phjwHigh· 7.5
3mo ago

Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

▾ Twilightwwbn · wwbn/avideovia GHSA
GHSA-xj9w-cgqg-q897Medium· 6.5
3mo ago

Duplicate Advisory: AVideo has Unauthenticated PGP Message Decryption via Public Endpoint

Duplicate Advisory: AVideo has Unauthenticated PGP Message Decryption via Public Endpoint

▾ Sunlitwwbn · wwbn/avideovia GHSA
GHSA-vfm7-4h43-gp6mMedium· 4.3
3mo ago

Duplicate Advisory: vLLM Vulnerable to Regular Expression Denial of Service

Duplicate Advisory: vLLM Vulnerable to Regular Expression Denial of Service

▾ Sunlitvllm · vllmvia GHSA
GHSA-xppm-jmw6-fhmfLow
3mo ago

Duplicate Advisory: Cross-site scripting via <NoScript> slot content in Nuxt's head components

Duplicate Advisory: Cross-site scripting via <NoScript> slot content in Nuxt's head components

▾ Sunlitnuxt · nuxtvia GHSA
MAL-2026-6246None
3mo ago

Malicious code in d0rk3r (PyPI)

Malicious code in d0rk3r (PyPI)

▾ Sunlitd0rk3r · d0rk3rvia OSV
MAL-2026-6245None
3mo ago

Malicious code in request-cache-py (PyPI)

Malicious code in request-cache-py (PyPI)

▾ Sunlitrequest-cache-py · request-cache-pyvia OSV
MAL-2026-6236None
3mo ago

Malicious code in query-profile (PyPI)

Malicious code in query-profile (PyPI)

▾ Sunlitquery-profile · query-profilevia OSV

Most-affected vendors

By CVEs published in the period.