VulnSea

Daily digest

Tuesday 21 July 2026

A heavy day: 310 new CVEs, well above the recent average of about 157. Severity skewed high: 42 critical and 133 high, 56% of the total. 11 arrived with exploitation evidence or public exploit code already attached. CISA added 3 CVEs to the Known Exploited Vulnerabilities catalog. oracle was the most-affected vendor with 154.

310
New CVEs
42
Critical
3
KEV additions
3
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 310 published.

CVE-2016-20096Critical· 9.8PoC
2mo ago

Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp

Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name parameter in a POST request to the login e…

▾ AbyssalKunshi Network Technology Co., Ltd. · Linknat VOS3000EPSS 0.67%via CVEORG
CVE-2026-59891Critical· 9.6PoC
2mo ago

Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry

Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry

▾ Abyssalsigstore · @sigstore/ociEPSS 0.47%via GHSA
CVE-2026-65057Critical· 9.3PoC
2mo ago

Keep Unauthenticated Server-Side Request Forgery via POST /providers/healthcheck

Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthchec…

▾ Abyssalkeephq · keepEPSS 0.43%via CVEORG
CVE-2026-58424High· 8.9PoC
2mo ago

Gitea: Permanent Fork PR Workflow Approval Gate Bypass

Gitea: Permanent Fork PR Workflow Approval Gate Bypass

▾ Midnightgitea · code.gitea.io/giteaEPSS 0.37%via GHSA
CVE-2026-65318High· 8.6PoC
2mo ago

Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader

Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled UR…

▾ MidnightWeaviate · VerbaEPSS 0.60%via CVEORG
CVE-2026-65317High· 8.6PoC
2mo ago

Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass

Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by suppl…

▾ MidnightWeaviate · VerbaEPSS 0.64%via CVEORG
CVE-2026-63764High· 8.6PoC
2mo ago

LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original U…

LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original U…

▾ Midnightinternlm · lmdeployEPSS 0.51%via NVD
CVE-2026-65056High· 8.2PoC
2mo ago

mcp-webresearch Server-Side Request Forgery in visit_page Due to Missing Internal-IP Filtering

mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only valida…

▾ Midnightmzxrai · mcp-webresearchEPSS 0.41%via CVEORG
CVE-2026-60568Critical· 9.9
2mo ago

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools)

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged att…

▾ Midnightoracle · webcenter_portalEPSS 0.43%via NVD
CVE-2026-60565Critical· 9.9
2mo ago

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools)

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged att…

▾ Midnightoracle · webcenter_portalEPSS 0.43%via NVD
CVE-2026-60562Critical· 9.9
2mo ago

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools)

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged att…

▾ Midnightoracle · webcenter_portalEPSS 0.43%via NVD
CVE-2026-60561Critical· 9.9
2mo ago

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools)

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged att…

▾ Midnightoracle · webcenter_portalEPSS 0.43%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-63030WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…81
  • CVE-2026-0770Langflow affected by Remote Code Execution via validate_code() exec()79
  • CVE-2026-60137WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.59

Most-affected vendors

By CVEs published in the period.