VulnSea

Daily digest

Saturday 18 July 2026

83 new CVEs this day, in line with the recent average. Of those, 3 critical and 28 high. 2 arrived with exploitation evidence or public exploit code already attached.

83
New CVEs
3
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 83 published.

MAL-2026-10779Critical⚠ Exploited
2mo ago

Malicious code in mlflow-ui (PyPI)

Malicious code in mlflow-ui (PyPI)

▾ Abyssalmlflow-ui · mlflow-uivia OSV
CVE-2026-9147High· 7.8PoC
2mo ago

uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime

uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (for example, streamer element names) are interpolated into the gen…

▾ MidnightEPSS 0.22%via NVD
CVE-2026-16117Critical· 10.0
2mo ago

Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded

Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for route matching, but request.url retains the original encode…

▾ MidnightEPSS 0.44%via NVD
CVE-2026-47865Critical· 9.8
2mo ago

VMware Avi Load Balancer contains an authentication bypass vulnerability

VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.1.1 through 31.2…

▾ MidnightEPSS 0.61%via NVD
CVE-2026-47871High· 8.8
2mo ago

VMware Avi Load Balancer contains a directory traversal vulnerability

VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1…

▾ TwilightEPSS 0.96%via NVD
CVE-2026-16097High· 8.8
2mo ago

A vulnerability was found in Shibby Tomato 1.28

A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-based buffer overflow. It is possible to la…

▾ TwilightEPSS 0.79%via NVD
CVE-2026-16096High· 8.8
2mo ago

A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124

A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads to stack-based buffer overflow. It is possible to initiate…

▾ TwilightEPSS 0.79%via NVD
CVE-2026-16095High· 8.8
2mo ago

A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124

A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. Affected by this issue is the function setup_conntrack of the file /sbin/rc. Executing a manipulation of the argument ct_tcp_timeout can lead to out-of-bounds write. Th…

▾ TwilightEPSS 0.73%via NVD
CVE-2026-11826High· 8.8
2mo ago

OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp

OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp. getData() reads characters between two delimiters into a caller-supplied buffer with no size parameter and no bounds check. I…

▾ TwilightEPSS 0.75%via NVD
CVE-2024-58362High· 8.8
2mo ago

SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for non-computed values

SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for non-computed values. When a record access method defines a S…

▾ TwilightEPSS 0.64%via NVD
CVE-2026-47869High· 8.7
2mo ago

VMware Avi Load Balancer contains a remote code execution vulnerability

VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed…

▾ TwilightEPSS 0.74%via NVD
CVE-2026-47867High· 8.7
2mo ago

VMware Avi Load Balancer contains a remote code execution vulnerability

VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 thro…

▾ TwilightEPSS 0.74%via NVD

Most-affected vendors

By CVEs published in the period.