VulnSea

Daily digest

Friday 14 August 2026

A quiet day: only 56 new CVEs against a recent average of about 209. Of those, 5 critical and 20 high. 3 arrived with exploitation evidence or public exploit code already attached. getgrav was the most-affected vendor with 4.

56
New CVEs
5
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 56 published.

CVE-2026-16772High· 8.1PoC
1mo ago

In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges

In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges. This vulnerability is caused by a flaw in the `UpdateUser` j…

MidnightAkaunting · AkauntingEPSS 0.25%via NVD
CVE-2026-69414High· 7.8PoC
1mo ago

Microsoft Defender Elevation of Privilege Vulnerability

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;ShieldBreak &quot;.

MidnightMicrosoft · Microsoft Malware Protection EngineEPSS 0.56%via CVEORG
CVE-2026-19188Critical· 10.0
1mo ago

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails …

MidnightEPSS 1.9%via NVD
CVE-2026-73849Critical· 9.8
1mo ago

Emlog is an open source website building system

Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the guard runs only when $act != 'reinstall'. …

MidnightEPSS 0.59%via NVD
CVE-2026-50027Critical· 9.8
1mo ago

mcp-memory-service is a semantic memory layer for AI applications

mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with a…

Midnightmcp-memory-service · mcp-memory-serviceEPSS 0.50%via NVD
CVE-2026-48528Critical· 9.8
1mo ago

Metacat is data repository software that helps researchers preserve, share, and discover data

Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in the `/cn/v1/object` and `/cn/v2/object` REST AP…

MidnightEPSS 0.40%via NVD
CVE-2026-49457Critical· 9.1
1mo ago

erlang_quic is a pure Erlang QUIC implementation

erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not valida…

Midnightquic · quicEPSS 0.15%via NVD
CVE-2026-73847Medium· 6.8PoC
1mo ago

Emlog is an open source website building system

Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an att…

TwilightEPSS 0.20%via NVD
CVE-2026-72827High· 8.8
1mo ago

Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands

Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands. Attackers can inject Twig payloads using th…

TwilightEPSS 0.62%via NVD
CVE-2026-72819High· 8.8
1mo ago

Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code

Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can byp…

Twilightgetgrav · getgrav/gravEPSS 0.50%via NVD
GHSA-wvxr-6v52-gfmhHigh· 8.8
1mo ago

Duplicate Advisory: Remote code execution via .zip file upload in Grav CMS

Duplicate Advisory: Remote code execution via .zip file upload in Grav CMS

Twilightgetgrav · getgrav/gravvia GHSA
CVE-2026-72837High· 8.8
1mo ago

File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths

File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files be…

TwilightEPSS 0.30%via NVD

Most-affected vendors

By CVEs published in the period.