VulnSea

Daily digest

Sunday 28 June 2026

A quiet day: only 19 new CVEs against a recent average of about 80. Of those, 5 high. One arrived with exploitation evidence or public exploit code already attached.

19
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 19 published.

CVE-2026-10643High· 8.7
3mo ago

Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user-supplied ancillary (msg_control) buffer using only the payload length (msg->msg_controllen < pktinfo_len) before wri…

Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user-supplied ancillary (msg_control) buffer using only the payload length (msg->msg_controllen < pktinfo_len) before wri…

▾ Twilightzephyrproject · zephyrEPSS 0.16%via NVD
CVE-2026-58049High· 8.6
3mo ago

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a P…

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a P…

▾ TwilightRed Hat · Red Hat Enterprise Linux AI 3.0 for RHEL 9EPSS 0.50%via NVD
CVE-2026-58056High· 7.6
3mo ago

RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags

RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can …

▾ TwilightEPSS 0.33%via NVD
CVE-2026-10646High· 7.4
3mo ago

Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getaddrinfo.c) passes a pointer to a stack-allocated state object (struct getaddrinfo_state ai_state) as the user_data of an asynchronous DNS resolver query

Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getaddrinfo.c) passes a pointer to a stack-allocated state object (struct getaddrinfo_state ai_state) as the user_data of an asynchronous DNS resolver query. The s…

▾ Twilightzephyrproject · zephyrEPSS 0.45%via NVD
CVE-2026-13500High· 7.3
3mo ago

A weakness has been identified in antlr ANTLR4 up to 4.13.2

A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/OutputFile.java of the component Grammar Action Block Handler. Executing a manipulation can lead…

▾ TwilightEPSS 0.52%via NVD
CVE-2026-13512Medium· 6.3
3mo ago

A vulnerability was identified in Databend up to 1.2.881 on HTTP

A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_key of the file src/query/service/src/servers/http/v1/session/client_session_manager.rs of the component Tenant Handl…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-13509Medium· 6.3
3mo ago

A vulnerability has been found in RAGapp up to 0.1.5

A vulnerability has been found in RAGapp up to 0.1.5. Affected is the function FileHandler.upload_file/FileHandler.remove_file of the file src/ragapp/backend/controllers/files.py of the component Knowledge File Handler. Such manipulation…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-13508Medium· 5.5
3mo ago

A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28

A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28. This impacts an unknown function of the file src/khoj/routers/api_chat.py of the component Conversation Sharing Handler. This manipulation of the argument conversation.agent caus…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-13503Medium· 5.3
3mo ago

A vulnerability was detected in antlr ANTLR4 up to 4.13.2

A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile of the file tool/src/org/antlr/v4/parse/TokenVocabParser.java of the component tokenVocab Grammar Option Handler. The …

▾ SunlitEPSS 0.77%via NVD
CVE-2026-13501Medium· 5.3
3mo ago

A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2

A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2. Affected by this vulnerability is the function GoTarget of the file tool/src/org/antlr/v4/codegen/target/GoTarget.java of the component gofmt. The manipulation lead…

▾ SunlitEPSS 1.2%via NVD
CVE-2026-13507Medium· 5.0
3mo ago

A vulnerability was detected in volcengine OpenViking up to 0.3.21

A vulnerability was detected in volcengine OpenViking up to 0.3.21. This affects the function str_to_uint64 of the file openviking/storage/vectordb/utils/str_to_uint64.py of the component Local VectorDB Primary-key Label Handler. The man…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-13502Medium· 4.5
3mo ago

A flaw has been found in antlr ANTLR4 up to 4.13.2

A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main/java/org/antlr/mojo/antlr4/GrammarDependencies.java of the component Maven Plugin. This m…

▾ SunlitEPSS 0.11%via NVD

Most-affected vendors

By CVEs published in the period.