VulnSea

Daily digest

Wednesday 26 August 2026

118 new CVEs this day, in line with the recent average. Severity skewed high: 19 critical and 56 high, 64% of the total. 4 arrived with exploitation evidence or public exploit code already attached. CISA added 5 CVEs to the Known Exploited Vulnerabilities catalog. winter was the most-affected vendor with 7.

118
New CVEs
19
Critical
5
KEV additions
5
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

CVE-2021-23758High· 8.1CISA KEVPoC
4y ago

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

Abyssalajaxpro.2_project · ajaxpro.2EPSS 84%via NVD
CVE-2019-1068High· 8.8CISA KEVPoC
7y ago

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

Abyssalmicrosoft · sql_serverEPSS 53%via NVD
CVE-2022-0995High· 7.8CISA KEVPoC
4y ago

An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem

An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a …

Abyssallinux · linux_kernelEPSS 9.4%via NVD
CVE-2015-5287High· 7.8CISA KEVPoC
10y ago

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/a…

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/a…

Abyssalredhat · automatic_bug_reporting_toolEPSS 5.0%via NVD
CVE-2015-3246Medium· 5.1CISA KEVPoC
11y ago

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an erro…

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an erro…

Midnightredhat · libuserEPSS 8.8%via NVD

New this day, ranked by depth score

The 12 that matter most of the 118 published.

CVE-2026-60004Critical· 9.8CISA KEV0dayPoC
4w ago

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

HadalGitea · GiteaEPSS 87%via CVEORG
MAL-2026-14545Critical⚠ Exploited
4w ago

Malicious code in pybitjs (PyPI)

Malicious code in pybitjs (PyPI)

Abyssalpybitjs · pybitjsvia OSV
CVE-2026-80428Critical· 9.8PoC
4w ago

ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication end…

ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication end…

AbyssalEPSS 2.3%via NVD
CVE-2026-80521High· 7.8PoC
4w ago

In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partially. The scenario is as follows: 1) Create two SCCs: …

In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partially. The scenario is as follows: 1) Create two SCCs: …

MidnightLinux · LinuxEPSS 0.13%via NVD
CVE-2026-65646Critical· 9.9
4w ago

Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.

Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.

MidnightWebPros · PleskEPSS 0.39%via CVEORG
CVE-2026-80349Critical· 9.8
4w ago

TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header

TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header. app.js sets Koa's proxy option to true without naming which upstream proxies may be trusted and without limiting the number of forwarde…

MidnightEPSS 0.45%via NVD
CVE-2026-80203Critical· 9.8
4w ago

The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints

The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses isSuperAdmin() on the acting …

MidnightEPSS 0.39%via NVD
CVE-2026-75338Critical· 9.8
4w ago

disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control

disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/config/list and /api/config/simple/list are exposed without authe…

MidnightEPSS 0.33%via NVD
CVE-2026-75325Critical· 9.8
4w ago

DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters.

DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters.

MidnightEPSS 0.35%via NVD
CVE-2026-54569Critical· 9.8
4w ago

senaite.core Vulnerable to Eval Injection and Missing Authorization

senaite.core Vulnerable to Eval Injection and Missing Authorization

Midnightsenaite-core · senaite-coreEPSS 0.78%via OSV
CVE-2026-52103Critical· 9.8
4w ago

A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via s…

A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via s…

MidnightEPSS 0.57%via NVD
CVE-2025-70293Critical· 9.8
4w ago

An issue was discovered in Denx U-Boot before 2026.04

An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() wh…

MidnightEPSS 0.53%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-1068A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.84
  • CVE-2026-16232An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges89
  • CVE-2026-66066Action Pack is a framework for handling and responding to web requests70
  • CVE-2026-42167mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROG…58
  • CVE-2025-34027The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints24

Most-affected vendors

By CVEs published in the period.