VulnSea

Daily digest

Sunday 30 August 2026

96 new CVEs this day, in line with the recent average. Of those, 3 critical and 18 high. 3 arrived with exploitation evidence or public exploit code already attached. Red Hat was the most-affected vendor with 3.

96
New CVEs
3
Critical
0
KEV additions
2
Records changed

New this day, ranked by depth score

The 12 that matter most of the 96 published.

CVE-2026-82539Critical· 9.1PoC
3w ago

A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509

A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory …

AbyssalEPSS 0.60%via NVD
CVE-2026-82542Critical· 10.0
3w ago

A weakness has been identified in Tenda HG10 300001138

A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes b…

MidnightEPSS 0.64%via NVD
CVE-2026-15980Critical· 9.8
3w ago

The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5

The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate()…

MidnightEPSS 0.45%via NVD
CVE-2026-56718High· 7.5PoC
3w ago

AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path trav…

AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path trav…

MidnightEPSS 0.62%via NVD
CVE-2026-82654High· 8.9
3w ago

SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions

SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views doc…

TwilightEPSS 0.22%via NVD
CVE-2026-82653High· 8.9
3w ago

SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments

SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar pac…

TwilightEPSS 0.22%via NVD
CVE-2026-82642High· 8.8
3w ago

Readest is an open-source e-book reader built on Tauri

Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that forbade only the <script> tag (FORBID_TAGS: ['script']) in apps/readest-app/sr…

TwilightEPSS 0.38%via NVD
CVE-2026-82635High· 8.8
3w ago

Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization

Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences (for example ../Library/LaunchAgents/c…

TwilightEPSS 0.40%via NVD
CVE-2026-82547Medium· 6.5PoC
3w ago

A vulnerability was found in Linux Foundation Magma 1.9.0

A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks/amf/amf_fsm.cpp of the component Registration Complete Message Handler. The manipulation results in improper authent…

TwilightLinux Foundation · MagmaEPSS 0.44%via NVD
CVE-2026-82645High· 8.6
3w ago

AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint

AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and …

TwilightEPSS 0.13%via NVD
CVE-2026-82641High· 8.6
3w ago

Keploy versions 3.1.0 through 3.6.25, fixed in 3.6.26, bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data

Keploy versions 3.1.0 through 3.6.25, fixed in 3.6.26, bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/p…

TwilightEPSS 0.35%via NVD
CVE-2026-82549High· 8.3
3w ago

A vulnerability was identified in Linux Foundation Magma 1.9.0

A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be la…

TwilightEPSS 0.19%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2017-8046Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbi…83
  • CVE-2018-0101A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute c…82

Most-affected vendors

By CVEs published in the period.