VulnSea

Daily digest

Sunday 16 August 2026

A quiet day: only 51 new CVEs against a recent average of about 191. Of those, 4 critical and 12 high. opentofu was the most-affected vendor with 3.

51
New CVEs
4
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 51 published.

CVE-2026-19924Critical· 9.8
1mo ago

A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01

A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be …

MidnightEPSS 0.90%via NVD
CVE-2026-18432Critical· 9.8
1mo ago

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit…

MidnightEPSS 0.51%via NVD
CVE-2026-16098Critical· 9.8
1mo ago

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Con…

MidnightEPSS 0.64%via NVD
CVE-2026-14524Critical· 9.1
1mo ago

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible…

MidnightEPSS 0.70%via NVD
CVE-2026-16099High· 8.8
1mo ago

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for…

TwilightEPSS 0.57%via NVD
CVE-2026-14498High· 8.8
1mo ago

The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter

The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_a…

TwilightEPSS 0.53%via NVD
CVE-2026-17123High· 8.8
1mo ago

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attack…

TwilightEPSS 0.34%via NVD
RUSTSEC-2026-0290High· 7.4
1mo ago

pqc_kyber: AVX2 backend skips Fujisaki-Okamoto implicit rejection, enabling chosen-ciphertext key recovery

pqc_kyber: AVX2 backend skips Fujisaki-Okamoto implicit rejection, enabling chosen-ciphertext key recovery

Twilightpqc_kyber · pqc_kybervia OSV
RUSTSEC-2026-0288High· 7.4
1mo ago

cosmian_kyber: AVX2 backend skips Fujisaki-Okamoto implicit rejection, enabling chosen-ciphertext key recovery

cosmian_kyber: AVX2 backend skips Fujisaki-Okamoto implicit rejection, enabling chosen-ciphertext key recovery

Twilightcosmian_kyber · cosmian_kybervia OSV
CVE-2026-74792High· 7.5
1mo ago

Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing

Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayI…

TwilightEPSS 0.31%via NVD
CVE-2026-74787High· 7.5
1mo ago

Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection

Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger…

TwilightEPSS 0.34%via NVD
CVE-2026-73062High· 7.5
1mo ago

Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks

Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large intege…

TwilightEPSS 0.28%via NVD

Most-affected vendors

By CVEs published in the period.