VulnSea

Daily digest

Saturday 1 August 2026

A heavy day: 167 new CVEs, well above the recent average of about 92. Of those, 10 critical and 49 high. 6 arrived with exploitation evidence or public exploit code already attached. Red Hat was the most-affected vendor with 12.

167
New CVEs
10
Critical
0
KEV additions
2
Records changed

New this day, ranked by depth score

The 12 that matter most of the 167 published.

CVE-2026-15964Critical· 9.8PoC
1mo ago

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_aj…

AbyssalEPSS 0.63%via NVD
CVE-2026-67330Critical· 9.9
1mo ago

@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass

@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SS…

MidnightEPSS 0.35%via NVD
CVE-2026-67308Critical· 10.0
1mo ago

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metachar…

MidnightEPSS 0.54%via NVD
GHSA-cw2r-r7mw-j3hcCritical· 9.8
1mo ago

Duplicate Advisory: GitPython unsafe clone option gate bypass through joined short options

Duplicate Advisory: GitPython unsafe clone option gate bypass through joined short options

Midnightgitpython · gitpythonvia GHSA
CVE-2026-67342Critical· 9.8
1mo ago

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify d…

MidnightEPSS 0.32%via NVD
CVE-2026-67341Critical· 9.8
1mo ago

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION stat…

MidnightEPSS 0.32%via NVD
CVE-2026-67324Critical· 9.8
1mo ago

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Re…

MidnightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.38%via NVD
CVE-2026-67289Critical· 9.8
1mo ago

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client…

MidnightEPSS 0.40%via NVD
CVE-2026-66402Critical· 9.8
1mo ago

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names()

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Commo…

MidnightEPSS 0.29%via NVD
CVE-2026-67340High· 7.2PoC
1mo ago

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permi…

MidnightEPSS 0.60%via NVD
CVE-2026-3141Critical· 9.1
1mo ago

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This i…

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This i…

MidnightEPSS 0.56%via NVD
CVE-2026-67325High· 8.8
1mo ago

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like uplo…

TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 1.9%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2025-68493Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes th…65
  • CVE-2026-55450Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak63

Most-affected vendors

By CVEs published in the period.