VulnSea

Daily digest

Monday 13 July 2026

A busier-than-usual day with 97 new CVEs (recent average about 84). Of those, 6 critical and 30 high. 7 arrived with exploitation evidence or public exploit code already attached. nukeviet was the most-affected vendor with 5.

97
New CVEs
6
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 97 published.

CVE-2026-60121Critical· 9.8PoC
2mo ago

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument …

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument …

▾ Abyssalvitec · flamingoEPSS 3.3%via NVD
CVE-2026-15685High· 7.50day
2mo ago

Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to cre…

Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not require…

▾ Abyssalollama · ollamaEPSS 0.71%via OSV
CVE-2026-61463High· 8.8PoC
2mo ago

Shiori Authenticated Privilege Escalation via PATCH /api/v1/auth/account

Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without authorization checks. Attackers can escalate to administrator by submitting a crafted P…

▾ Midnightgo-shiori · shioriEPSS 0.52%via CVEORG
CVE-2026-61462High· 8.6PoC
2mo ago

mcp-gitlab Path Traversal via job_id Parameter

mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to e…

▾ Midnightzereight · mcp-gitlabEPSS 0.51%via CVEORG
CVE-2026-61498Critical· 9.8
2mo ago

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters i…

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters i…

▾ Midnightvitec · flamingoEPSS 4.0%via NVD
CVE-2026-4769Critical· 9.8
2mo ago

Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence

Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief p…

▾ MidnightEPSS 0.76%via NVD
CVE-2026-62240High· 7.4PoC
2mo ago

CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged

CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the secur…

▾ Midnightcrewai · crewaiEPSS 0.52%via NVD
CVE-2026-14453Critical· 9.6
2mo ago

This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution

This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution. The message_confirm field is stored without sanitization and rendered via Smarty with …

▾ MidnightEPSS 0.84%via NVD
CVE-2026-47677Critical
2mo ago

FacturaScripts: Account takeover of any 2FA-enabled user

FacturaScripts: Account takeover of any 2FA-enabled user

▾ Midnightfacturascripts · facturascripts/facturascriptsvia GHSA
CVE-2026-13221Critical· 9.1⚖ disputed
2mo ago

Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl…

Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl…

▾ Midnightperl · perlEPSS 0.43%via NVD
CVE-2026-15545High· 8.8
2mo ago

A vulnerability was identified in Shibby Tomato up to 1.28.0000

A vulnerability was identified in Shibby Tomato up to 1.28.0000. Affected by this vulnerability is the function main of the file www/apcupsd/tomatodata.cgi of the component apcupsd. Such manipulation leads to out-of-bounds write. The att…

▾ TwilightEPSS 0.73%via NVD
CVE-2026-15544High· 8.8
2mo ago

A vulnerability was determined in Shibby Tomato up to 1.28.0000

A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar of the file www/apcupsd/tomatodata.cgi of the component apcupsd. This manipulation of the argument Field causes stack-based buffer overfl…

▾ TwilightEPSS 0.79%via NVD

Most-affected vendors

By CVEs published in the period.