VulnSea

Daily digest

Friday 31 July 2026

A heavy day: 133 new CVEs, well above the recent average of about 80. Of those, 15 critical and 46 high. 8 arrived with exploitation evidence or public exploit code already attached. redhat was the most-affected vendor with 10.

133
New CVEs
15
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 133 published.

CVE-2026-52887Critical· 10.0PoC
1mo ago

NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

Abyssalnocobase · @nocobase/plugin-notification-in-app-messageEPSS 0.89%via GHSA
CVE-2026-17566Critical· 9.9PoC
1mo ago

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the…

AbyssalEPSS 0.56%via NVD
CVE-2026-68771Critical· 9.8PoC
1mo ago

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserial…

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserial…

AbyssalEPSS 0.78%via NVD
CVE-2026-63223Critical· 9.8PoC
1mo ago

CodeIgniter is a PHP full-stack web framework

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when a…

AbyssalEPSS 0.76%via NVD
CVE-2026-17351Critical· 9.0PoC
1mo ago

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TR…

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TR…

AbyssalEPSS 0.41%via NVD
CVE-2026-52855Critical· 9.9
1mo ago

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{co…

Midnightpterodactyl · github.com/pterodactyl/wingsEPSS 0.29%via NVD
CVE-2026-68770Critical· 9.8
1mo ago

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, wher…

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, wher…

MidnightEPSS 0.65%via NVD
CVE-2026-43830Critical· 9.8
1mo ago

tbc

Full details and mitigation steps are currently restricted and will be published at a later date.

Midnighttbc · tbcEPSS 0.33%via CVEORG
CVE-2026-16504Critical· 9.8
1mo ago

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.

MidnightEPSS 0.35%via NVD
CVE-2026-14537Critical· 9.8
1mo ago

Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocatio…

Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocatio…

Midnightgoogle · mcp_toolbox_for_databasesEPSS 0.22%via NVD
CVE-2026-62999High· 7.5PoC
1mo ago

Copier is a library and CLI app for rendering project templates

Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository prefix before an…

Midnightcopier-org · copierEPSS 0.37%via NVD
CVE-2026-54725Critical· 9.6
1mo ago

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, M…

Midnightbank-vaults · github.com/bank-vaults/vault-secrets-webhookEPSS 0.41%via NVD

Most-affected vendors

By CVEs published in the period.