VulnSea

Daily digest

Sunday 26 July 2026

A quiet day: only 17 new CVEs against a recent average of about 134. Of those, 8 high. One arrived with exploitation evidence or public exploit code already attached. Microsoft was the most-affected vendor with 3.

17
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 17 published.

CVE-2026-63720High· 7.5PoC
1mo ago

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded n…

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded n…

MidnightEPSS 0.75%via NVD
CVE-2026-15962High· 8.8
1mo ago

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subs…

TwilightEPSS 0.37%via NVD
CVE-2026-17497High· 8.3
1mo ago

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore in…

TwilightEPSS 0.46%via NVD
CVE-2026-17496High· 8.1
1mo ago

NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null

NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-cont…

TwilightEPSS 0.32%via NVD
CVE-2026-64530High· 7.8
1mo ago

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the defragmentation engine (e.g

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the defragmentation engine (e.g. act…

TwilightRed Hat · Red Hat Enterprise Linux BaseOS E4S (v.9.2)EPSS 0.54%via NVD
RUSTSEC-2026-0219High· 7.5
1mo ago

Remote Denial of Service via malformed NIP-04 IV

Remote Denial of Service via malformed NIP-04 IV

Twilightnostr · nostrvia OSV
CVE-2026-57990High· 7.4
1mo ago

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.50%via NVD
CVE-2026-57989High· 7.4
1mo ago

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.29%via NVD
CVE-2026-17458Medium· 6.3
1mo ago

A vulnerability was found in mf-yang openclaw-cn up to 0.2.1

A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server…

SunlitEPSS 0.28%via NVD
CVE-2026-17434Medium· 6.3
1mo ago

A flaw has been found in nanocoai NanoClaw up to 2.0.64

A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulation can lead to improper authorization…

SunlitEPSS 0.23%via NVD
CVE-2026-57978Medium· 5.4
1mo ago

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.14%via NVD
CVE-2026-17433Medium· 5.3
1mo ago

A vulnerability was detected in nanocoai NanoClaw up to 2.0.64

A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Performing a manipulation results in im…

SunlitEPSS 0.10%via NVD

Most-affected vendors

By CVEs published in the period.