VulnSea

Daily digest

Monday 6 July 2026

79 new CVEs this day, in line with the recent average. Severity skewed high: 10 critical and 33 high, 54% of the total. coder was the most-affected vendor with 18.

79
New CVEs
10
Critical
0
KEV additions
2
Records changed

New this day, ranked by depth score

The 12 that matter most of the 79 published.

GHSA-vjc7-jrh9-9j86Critical· 10.0
2mo ago

9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats

9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats

▾ Midnight9router · 9routervia GHSA
CVE-2026-55500Critical· 9.9
2mo ago

9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover

9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover

▾ Midnight9router · 9routerEPSS 0.69%via GHSA
CVE-2026-54769Critical· 10.0
2mo ago

Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent

Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent

▾ Midnightlangroid · langroidEPSS 0.91%via GHSA
CVE-2026-24014Critical· 9.8
2mo ago

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path wit…

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an…

▾ Midnightapache-iotdb · apache-iotdbEPSS 0.69%via OSV
CVE-2026-55615Critical
2mo ago

Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879

Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879

▾ Midnightlangroid · langroidEPSS 0.46%via GHSA
CVE-2026-54760Critical
2mo ago

Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls

Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls

▾ Midnightlangroid · langroidEPSS 0.65%via GHSA
CVE-2026-54496Critical· 9.3
2mo ago

Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness

Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness

▾ Midnightzebrad · zebradEPSS 0.32%via GHSA
CVE-2026-49445Critical· 9.2
2mo ago

Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access

Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access

▾ Midnightcilium · github.com/cilium/ciliumEPSS 0.17%via GHSA
CVE-2026-53486Critical· 9.1
2mo ago

Decompress: Archive extraction can create files and links outside of the target directory

Decompress: Archive extraction can create files and links outside of the target directory

▾ Midnightxhmikosr · @xhmikosr/decompressEPSS 0.75%via GHSA
CVE-2026-24013Critical· 9.1
2mo ago

Authentication Bypass by Spoofing vulnerability in Apache IoTDB.

Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing open…

▾ Midnightapache-iotdb · apache-iotdbEPSS 0.64%via OSV
CVE-2026-55429High· 8.7
2mo ago

Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID

Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.51%via GHSA
GHSA-qrwj-vh9x-gw5vHigh· 8.3
2mo ago

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write

▾ Twilightcoder · github.com/coder/coder/v2via GHSA

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2022-25060TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.80
  • CVE-2022-30023Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.74

Most-affected vendors

By CVEs published in the period.