VulnSea

Daily digest

Monday 20 July 2026

91 new CVEs this day, in line with the recent average. Of those, 7 critical and 26 high. 4 arrived with exploitation evidence or public exploit code already attached. axios was the most-affected vendor with 10.

91
New CVEs
7
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 91 published.

CVE-2026-61736Critical· 9.3PoC
2mo ago

LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests

LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests

▾ Abyssallightrag-hku · lightrag-hkuEPSS 1.4%via GHSA
CVE-2026-63769High· 7.7PoC
2mo ago

Huginn before 2026.09.09 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs

Huginn before 2026.09.09 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe inter…

▾ Midnighthuginn · huginnEPSS 0.41%via NVD
CVE-2026-15899Critical· 9.6
2mo ago

Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

▾ Midnightgoogle · chromeEPSS 0.40%via NVD
CVE-2026-61740Critical
2mo ago

LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection

LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection

▾ Midnightlightrag-hku · lightrag-hkuEPSS 0.66%via GHSA
CVE-2026-16242Critical· 9.4
2mo ago

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not va…

▾ MidnightRed Hat · multicluster-engine/hypershift-rhel9-operatorEPSS 0.80%via NVD
CVE-2026-39878Critical· 9.3
2mo ago

Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser session, le…

Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser session, le…

▾ MidnightEPSS 0.43%via NVD
CVE-2026-44231Critical· 9.1
2mo ago

RT is an open source, enterprise-grade issue and ticket tracking system

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged…

▾ Midnightbestpractical · request_trackerEPSS 0.41%via NVD
CVE-2026-35198Critical· 9.0
2mo ago

HeyForm is an open-source form builder

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes when a team owner…

▾ MidnightEPSS 0.49%via NVD
CVE-2026-64206High· 8.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock l2cap_conn_del() takes conn->lock and then calls cancel_work_sync() for pending_rx_work

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock l2cap_conn_del() takes conn->lock and then calls cancel_work_sync() for pending_rx_work. process_pen…

▾ TwilightEPSS 0.26%via NVD
CVE-2026-63728Medium· 6.3PoC
2mo ago

Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Feature

Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitive data by leveraging non-hermetic Spri…

▾ Twilightgitleaks · gitleaksEPSS 0.21%via CVEORG
CVE-2026-61836High· 8.6
2mo ago

Directus: Authorization-dependent response served from unsegmented cache key

Directus: Authorization-dependent response served from unsegmented cache key

▾ Twilightdirectus · directusEPSS 0.47%via GHSA
CVE-2026-62685High· 8.1
2mo ago

File Browser: Colliding username normalization gives two users the same home directory

File Browser: Colliding username normalization gives two users the same home directory

▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.55%via GHSA

Most-affected vendors

By CVEs published in the period.