VulnSea

Daily digest

Thursday 23 July 2026

A quiet day: only 45 new CVEs against a recent average of about 113. Severity skewed high: 8 critical and 22 high, 67% of the total. 7 arrived with exploitation evidence or public exploit code already attached. pypdf was the most-affected vendor with 4.

45
New CVEs
8
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 45 published.

CVE-2026-15630Critical· 9.9PoC
2mo ago

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).

AbyssalCasdoor · CasdoorEPSS 0.34%via NVD
CVE-2026-65606Critical· 9.6PoC
2mo ago

SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler

SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an installed plugin, the application opens a custom tab and inserts t…

Abyssalsiyuan-note · siyuanEPSS 0.65%via NVD
CVE-2026-65605Critical· 9.6PoC
2mo ago

SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering

SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied wh…

Abyssalsiyuan-note · siyuanEPSS 0.65%via NVD
CVE-2026-63765High· 8.2PoC
2mo ago

Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account

Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing au…

Midnightchatwoot · chatwootEPSS 0.70%via NVD
CVE-2026-64600High· 7.8PoC
2mo ago

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapp…

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapp…

MidnightEPSS 0.47%via NVD
CVE-2026-54120Critical· 9.9
2mo ago

Microsoft Surface Remote Code Execution Vulnerability

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

MidnightMicrosoft · Surface Management ServicesEPSS 0.71%via CVEORG
CVE-2026-44210Critical· 9.9
2mo ago

kata-containers: Kata Containers: Privilege escalation and information disclosure via command-line argument injection (CVE-2026-44210)

A flaw was found in Kata Containers, an open-source project that provides lightweight virtual machines (VMs) for containers. A user with privileges to create pods can inject malicious command-line arguments into the virtiofsd process, whic…

MidnightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.50%via CSAF
CVE-2026-65919High· 7.5PoC
2mo ago

Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly to os.Open without path validation

Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly to os.Open without path validation. A…

Midnightmeshery · mesheryEPSS 2.1%via NVD
CVE-2026-56165Critical· 9.8
2mo ago

Microsoft Account Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

MidnightMicrosoft · Microsoft AccountEPSS 0.72%via CVEORG
GHSA-8fpg-xm3f-6cx3Critical
2mo ago

Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)

Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)

Midnightnext-auth · next-authvia GHSA
GHSA-7rqj-j65f-68whCritical
2mo ago

Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass

Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass

Midnightauth · @auth/corevia GHSA
CVE-2026-65918High· 7.1PoC
2mo ago

PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy

PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. Attackers can supply malicious or trunc…

Midnightlinuxfoundation · torchvisionEPSS 0.33%via NVD

Most-affected vendors

By CVEs published in the period.