VulnSea

Daily digest

Wednesday 22 July 2026

98 new CVEs this day, in line with the recent average. Of those, 1 critical and 39 high. 4 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. n8n was the most-affected vendor with 53.

98
New CVEs
1
Critical
2
KEV additions
4
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 98 published.

CVE-2026-16232Critical· 9.1CISA KEV0dayPoC
2mo ago

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successfu…

Hadalcheckpoint · multi-domain_security_managementEPSS 72%via NVD
CVE-2026-65013High· 8.8PoC
2mo ago

Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API…

Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API…

Midnightonlook · repoEPSS 0.37%via NVD
CVE-2026-65591HighPoC
2mo ago

n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution

n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution

Midnightn8n · n8nEPSS 0.48%via GHSA
CVE-2026-64641High
2mo ago

Next.js: Denial of Service in App Router using Server Actions

Next.js: Denial of Service in App Router using Server Actions

Twilightnext · nextEPSS 1.4%via GHSA
CVE-2026-59208High
2mo ago

n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution

n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution

Twilightn8n · n8nEPSS 3.1%via GHSA
GHSA-xwx6-jjhv-84p8High
2mo ago

n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service

n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service

Twilightn8n · n8nvia GHSA
GHSA-xmc9-4f2h-jf9cHigh
2mo ago

n8n: Edit Image Node Format Injection Allows Arbitrary File Write

n8n: Edit Image Node Format Injection Allows Arbitrary File Write

Twilightn8n · n8nvia GHSA
GHSA-wq64-hcrf-8m56High
2mo ago

Duplicate Advisory: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs

Duplicate Advisory: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs

Twilightn8n · n8nvia GHSA
GHSA-w46p-w7w2-fr9gHigh
2mo ago

Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool

Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool

Twilightn8n · n8nvia GHSA
GHSA-vhcw-f978-xjjgHigh
2mo ago

Duplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview

Duplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview

Twilightn8n · n8nvia GHSA
GHSA-rcv6-pvrj-4xcgHigh
2mo ago

n8n: Authenticated code execution in the n8n Git node

n8n: Authenticated code execution in the n8n Git node

Twilightn8n · n8nvia GHSA
GHSA-pppj-hq3g-57pjHigh
2mo ago

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

Twilightjupyterlab · jupyterlabvia GHSA

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-63030WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…98
  • CVE-2026-56290The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.85
  • CVE-2026-0770Langflow affected by Remote Code Execution via validate_code() exec()79
  • CVE-2026-60137WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.73

Most-affected vendors

By CVEs published in the period.