VulnSea

Daily digest

Tuesday 23 June 2026

101 new CVEs this day, in line with the recent average. Of those, 9 critical and 37 high. 8 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. gogs was the most-affected vendor with 16.

101
New CVEs
9
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 101 published.

CVE-2026-52806Critical· 9.9PoC
3mo ago

Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge

Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge

▾ Abyssalgogs · gogs.io/gogsEPSS 7.9%via GHSA
CVE-2026-54350Critical· 10.0PoC
3mo ago

Budibase has nonymous NoSQL operator injection via published-app query templates

Budibase has nonymous NoSQL operator injection via published-app query templates

▾ Abyssalbudibase · @budibase/serverEPSS 0.54%via GHSA
CVE-2026-52813Critical· 10.0PoC
3mo ago

Gogs has Path Traversal in organization name that results in RCE through Git hooks

Gogs has Path Traversal in organization name that results in RCE through Git hooks

▾ Abyssalgogs · gogs.io/gogsEPSS 1.1%via GHSA
CVE-2026-54512High· 8.1PoC
3mo ago

jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)

A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass the PolymorphicTypeValidator (PTV) when polymorphic typing is enabled and a type identifier contains generic parameters. By crafting a malicious ty…

▾ MidnightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 1.00%via CSAF
GHSA-qxvg-h7q2-hcxhCritical· 9.8
3mo ago

motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)

motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)

▾ Midnightmotioneye · motioneyevia GHSA
GHSA-g7vj-qw6x-g3p8Critical· 9.8
3mo ago

Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist

Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist

▾ Midnightpicklescan · picklescanvia GHSA
CVE-2026-12866Critical· 9.8
3mo ago

expr-eval vulnerable to Code Execution

expr-eval vulnerable to Code Execution

▾ Midnightexpr-eval · expr-evalEPSS 0.87%via GHSA
CVE-2026-52810HighPoC
3mo ago

Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion

Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion

▾ Midnightgogs · gogs.io/gogsEPSS 0.43%via GHSA
CVE-2026-11807Critical· 9.6
3mo ago

A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API

A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send …

▾ MidnightEPSS 0.53%via NVD
GHSA-phv5-334h-mxcwCritical
3mo ago

motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal

motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal

▾ Midnightmotioneye · motioneyevia GHSA
CVE-2026-52811Critical
3mo ago

Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym

Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym

▾ Midnightgogs · gogs.io/gogsEPSS 0.47%via GHSA
CVE-2026-41862High· 8.8
3mo ago

Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to re…

Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to re…

▾ Twilightbroadcom · spring_statemachineEPSS 0.76%via NVD

Most-affected vendors

By CVEs published in the period.