VulnSea

Daily digest

Tuesday 28 July 2026

58 new CVEs this day, in line with the recent average. Severity skewed high: 5 critical and 34 high, 67% of the total. One arrived with exploitation evidence or public exploit code already attached. datamodel-code-generator was the most-affected vendor with 12.

58
New CVEs
5
Critical
0
KEV additions
1
Records changed

New this day, ranked by depth score

The 12 that matter most of the 58 published.

CVE-2026-66748High· 8.8PoC
1mo ago

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the…

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the…

MidnightEPSS 0.83%via NVD
CVE-2026-54658Critical· 9.8
1mo ago

@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution

@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution

Midnighthypequery · @hypequery/clickhouseEPSS 0.46%via GHSA
CVE-2026-54588Critical· 9.6
1mo ago

Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.

Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.

Midnightpoweradmin · poweradmin/poweradminEPSS 0.54%via GHSA
CVE-2026-11841Critical· 9.4
1mo ago

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed throu…

MidnightEPSS 0.49%via NVD
CVE-2026-64863Critical· 9.1
1mo ago

goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite

goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite

Midnightgoshs · goshs.de/goshs/v2EPSS 0.36%via GHSA
CVE-2026-62325Critical· 9.1
1mo ago

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)

Midnightpatrickhener · github.com/patrickhener/goshs/v2EPSS 0.34%via GHSA
CVE-2026-55771High· 8.8
1mo ago

Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities

Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities

Twilightcedarpolicy · com.cedarpolicy:cedar-javaEPSS 0.57%via GHSA
CVE-2026-54653High· 8.8
1mo ago

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.45%via OSV
CVE-2026-54639High· 8.8
1mo ago

Style Dictionary - Prototype Pollution in convertTokenData utility function

Style Dictionary - Prototype Pollution in convertTokenData utility function

Twilightstyle-dictionary · style-dictionaryEPSS 0.36%via GHSA
CVE-2026-54650High· 8.6
1mo ago

openhole exposes localhost to the internet in one command

openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target with r.URL.EscapedPath(), allowing…

Twilightbablilayoub · github.com/bablilayoub/openholeEPSS 0.36%via NVD
CVE-2026-54609High· 8.6
1mo ago

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

Twilightquietterminal · com.quietterminal:qti-neonEPSS 0.26%via GHSA
CVE-2026-54603High· 8.6
1mo ago

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC)

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority,…

Twilightoauth2 · oauth2EPSS 0.43%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

Most-affected vendors

By CVEs published in the period.