VulnSea

Daily digest

Thursday 13 August 2026

223 new CVEs this day, in line with the recent average. Severity skewed high: 19 critical and 110 high, 58% of the total. 8 arrived with exploitation evidence or public exploit code already attached. Red Hat was the most-affected vendor with 31.

223
New CVEs
19
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 223 published.

CVE-2026-73570High· 8.9CISA KEVPoC
1mo ago

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP …

Abyssalsynacor · zimbra_collaboration_suiteEPSS 32%via NVD
CVE-2026-49819Critical· 9.8PoC
1mo ago

UpSnap is a wake on lan web app

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superu…

Abyssalseriousm4x · UpSnapEPSS 0.79%via NVD
CVE-2026-14669High· 8.8PoC
1mo ago

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreS…

Midnightpostgresql · postgresqlEPSS 0.68%via NVD
CVE-2026-72840High· 8.8PoC
1mo ago

OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration

OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL …

Midnightopenwrt · luciEPSS 0.38%via NVD
CVE-2026-14662High· 8.8PoC
1mo ago

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary …

Midnightpostgresql · postgresqlEPSS 0.46%via NVD
CVE-2026-73656Critical· 9.9
1mo ago

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateDeploymentBackgroundWorkerServiceV4.call() in apps/webapp/a…

MidnightEPSS 0.34%via NVD
CVE-2026-73602Critical· 9.9
1mo ago

Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass

Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object …

Midnightflowiseai · flowiseEPSS 0.84%via NVD
CVE-2026-72842Critical· 9.9
1mo ago

luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks

luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%…

MidnightEPSS 0.42%via NVD
CVE-2026-72841Critical· 9.9
1mo ago

luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory

luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious …

MidnightEPSS 0.53%via NVD
CVE-2026-73649Critical· 9.8
1mo ago

Velocity.js is a JavaScript implementation of the Apache Velocity template engine

Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.t…

MidnightEPSS 0.64%via NVD
CVE-2026-73533Critical· 9.8
1mo ago

Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server

Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTabl…

MidnightWPManageNinja · Ninja Tables ProEPSS 0.45%via NVD
CVE-2026-73532Critical· 9.8
1mo ago

Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server

Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), …

MidnightWPManageNinja · Fluent Forms ProEPSS 0.46%via NVD

Most-affected vendors

By CVEs published in the period.