VulnSea

Daily digest

Wednesday 15 July 2026

A quiet day: only 71 new CVEs against a recent average of about 167. Of those, 4 critical and 28 high. 3 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. mantisbt was the most-affected vendor with 8.

71
New CVEs
4
Critical
2
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 71 published.

CVE-2026-59258High· 8.3PoC
2mo ago

immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles without owner-only restrictions

immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles without owner-only restrictions. Attackers with editor access can dem…

▾ Midnightimmich-app · immichEPSS 0.46%via NVD
CVE-2026-13585High· 8.2PoC
2mo ago

Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive …

Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive …

▾ MidnightASUS · System Control Interface v3EPSS 0.16%via NVD
CVE-2026-52891Critical· 9.9
2mo ago

Wekan is open source kanban built with Meteor

Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for MIME-type detection. Because models/avatars.js and models/…

▾ MidnightEPSS 0.78%via NVD
CVE-2026-54466Critical
2mo ago

websocket-driver: Message corruption via abuse of protocol length headers

websocket-driver: Message corruption via abuse of protocol length headers

▾ Midnightwebsocket-driver · websocket-driverEPSS 0.38%via GHSA
CVE-2026-52881Critical
2mo ago

MantisBT: Reflected XSS in admin/install.php via unescaped printf

MantisBT: Reflected XSS in admin/install.php via unescaped printf

▾ Midnightmantisbt · mantisbt/mantisbtvia GHSA
CVE-2026-52847Critical
2mo ago

MantisBT: Reflected XSS in admin/install.php

MantisBT: Reflected XSS in admin/install.php

▾ Midnightmantisbt · mantisbt/mantisbtvia GHSA
CVE-2026-59255High· 7.1PoC
2mo ago

BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to modify the global graph schema

BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to modify the global graph schema. Attackers with valid session tokens…

▾ MidnightSpecterOps · BloodHoundEPSS 0.44%via NVD
GHSA-62gx-5q78-wrvxHigh· 8.8
2mo ago

obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/write/delete

obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/write/delete

▾ Twilightobsidian-local-rest-api · obsidian-local-rest-apivia GHSA
CVE-2026-54498High· 8.7
2mo ago

ViewComponent: around_render HTML-Safety Bypass

ViewComponent: around_render HTML-Safety Bypass

▾ Twilightview_component · view_componentEPSS 0.45%via GHSA
CVE-2026-20150High· 8.8
2mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresse…

▾ Twilightcisco · roomosEPSS 0.42%via NVD
CVE-2026-15029High· 8.4
2mo ago

Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL req…

Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL req…

▾ TwilightASUS · System Control Interface v3EPSS 0.17%via NVD
CVE-2026-20156High· 8.1
2mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresse…

▾ Twilightcisco · roomosEPSS 0.46%via NVD

Most-affected vendors

By CVEs published in the period.