VulnSea

Daily digest

Sunday 12 July 2026

70 new CVEs this day, in line with the recent average. Of those, 3 critical and 25 high. 4 arrived with exploitation evidence or public exploit code already attached.

70
New CVEs
3
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 70 published.

CVE-2026-61876High· 8.8PoC
2mo ago

LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup

LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the…

▾ MidnightEPSS 1.3%via NVD
CVE-2026-15511Critical· 9.8
2mo ago

A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8

A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of the file /usr/bin/webmgnt of the component FastCGI Backend. This manipulation of the argum…

▾ MidnightEPSS 4.7%via NVD
CVE-2026-56271Critical· 9.8
2mo ago

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication m…

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication m…

▾ MidnightEPSS 0.66%via NVD
CVE-2026-56260Critical· 9.1
2mo ago

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supp…

▾ Midnightcrawl4ai · crawl4aiEPSS 0.65%via NVD
CVE-2026-61875High· 8.8
2mo ago

luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests

luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests. Attackers can send malicious HTML in the NewPortMappingDescription…

▾ TwilightEPSS 0.55%via NVD
CVE-2026-59260High· 8.8
2mo ago

OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments

OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. Attackers can pass arbitrary Samba global o…

▾ TwilightEPSS 0.68%via NVD
CVE-2026-15484High· 8.8
2mo ago

A vulnerability was detected in TRENDnet TEW-821DAP 1.12B01

A vulnerability was detected in TRENDnet TEW-821DAP 1.12B01. The affected element is the function sub_41EC14 of the file /goform/tools_nslookup of the component ssi. The manipulation results in buffer overflow. It is possible to launch t…

▾ TwilightEPSS 0.79%via NVD
CVE-2026-15483High· 8.8
2mo ago

A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01

A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function sub_41EC14 of the file /goform/tools_nslookup of the component ssi. The manipulation of the argument nslookup_target leads to buffer over…

▾ TwilightEPSS 0.79%via NVD
CVE-2026-15481High· 8.8
2mo ago

A security flaw has been discovered in Trendnet TEW-635BRM up to 1.00.03

A security flaw has been discovered in Trendnet TEW-635BRM up to 1.00.03. This vulnerability affects the function ipoa_test of the file /sbin/rc of the component IPoA WAN Connection Setup. Performing a manipulation of the argument ipoa_i…

▾ TwilightEPSS 2.9%via NVD
CVE-2026-15480High· 8.8
2mo ago

A vulnerability was identified in Trendnet TEW-635BRM up to 1.00.03

A vulnerability was identified in Trendnet TEW-635BRM up to 1.00.03. This affects the function start_httpd of the file /sbin/rc of the component Web Service. Such manipulation of the argument device_name leads to stack-based buffer overf…

▾ TwilightEPSS 0.79%via NVD
CVE-2026-15502Medium· 6.3PoC
2mo ago

A vulnerability was detected in AojiaoZero Antaris 1.0

A vulnerability was detected in AojiaoZero Antaris 1.0. This affects the function _rewardPurchase of the file /ipn.php of the component PayPal IPN Payment Handler. The manipulation of the argument item_number results in sql injection. Th…

▾ TwilightEPSS 0.32%via NVD
CVE-2026-58596High· 8.3
2mo ago

Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.61%via NVD

Most-affected vendors

By CVEs published in the period.