VulnSea

Daily digest

Saturday 22 August 2026

99 new CVEs this day, in line with the recent average. Of those, 3 critical and 17 high. 4 arrived with exploitation evidence or public exploit code already attached. nltk was the most-affected vendor with 10.

99
New CVEs
3
Critical
0
KEV additions
1
Records changed

New this day, ranked by depth score

The 12 that matter most of the 99 published.

CVE-2026-77946Critical· 10.0
1mo ago

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulatio…

MidnightEPSS 0.62%via NVD
CVE-2026-78003Critical· 9.8
1mo ago

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which a…

MidnightEPSS 0.87%via NVD
CVE-2026-4703Critical· 9.8
1mo ago

The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values

The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This ma…

MidnightEPSS 0.62%via NVD
CVE-2026-71513High· 8.8
1mo ago

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables …

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables …

Twilightnltk · nltkEPSS 0.79%via NVD
CVE-2026-60084High· 8.7
1mo ago

SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly to os.RemoveAll

SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly to os.RemoveAll. Authenticated admin attackers can suppl…

TwilightEPSS 0.35%via NVD
CVE-2026-59808High· 8.8
1mo ago

AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogi…

AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogi…

TwilightEPSS 0.34%via NVD
CVE-2026-68766High· 7.8
1mo ago

hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path

hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append atta…

TwilightEPSS 0.16%via NVD
CVE-2026-57998High· 7.8
1mo ago

better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then pa…

better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then pa…

TwilightEPSS 0.14%via NVD
CVE-2026-77945High· 7.4
1mo ago

A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05

A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.cgi of the component ssi. Performing a manipulation of the argument filename results in command injection. The attack…

TwilightEPSS 1.3%via NVD
CVE-2026-66393High· 7.5
1mo ago

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exce…

Twilightnltk · nltkEPSS 0.36%via NVD
CVE-2026-63312High· 7.5
1mo ago

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open()

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can r…

Twilightnltk · nltkEPSS 0.56%via NVD
CVE-2026-62388High· 7.5
1mo ago

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by e…

TwilightEPSS 0.46%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-0770Langflow affected by Remote Code Execution via validate_code() exec()79

Most-affected vendors

By CVEs published in the period.