VulnSea

Daily digest

Friday 4 September 2026

A heavy day: 409 new CVEs, well above the recent average of about 148. Of those, 51 critical and 139 high. 78 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. ibm was the most-affected vendor with 43.

409
New CVEs
51
Critical
1
KEV additions
1
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 409 published.

MAL-2026-16044Critical⚠ Exploited
2w ago

Malicious code in tsshare (PyPI)

Malicious code in tsshare (PyPI)

▾ Abyssaltsshare · tssharevia OSV
MAL-2026-15931Critical⚠ Exploited
2w ago

Malicious code in metricboxlite (PyPI)

Malicious code in metricboxlite (PyPI)

▾ Abyssalmetricboxlite · metricboxlitevia OSV
CVE-2026-85688Critical· 9.8PoC
2w ago

TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints

TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to re…

▾ AbyssalTEN-framework · ten-frameworkEPSS 1.5%via NVD
CVE-2026-85672Critical· 9.8PoC
2w ago

zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities

zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities. Attac…

▾ Abyssalgetomni-ai · zeroxEPSS 1.5%via NVD
CVE-2026-78745Critical· 9.8PoC
2w ago

An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via the Android Debug Bridge (ADB) daemon (adbd)

An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via the Android Debug Bridge (ADB) daemon (adbd)

▾ AbyssalEPSS 0.72%via NVD
CVE-2026-75430Critical· 9.8PoC
2w ago

PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port

PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.

▾ AbyssalEPSS 0.89%via NVD
CVE-2026-75429Critical· 9.8PoC
2w ago

PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the Server-Worker transport layer

PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the Server-Worker transport layer

▾ AbyssalEPSS 0.90%via NVD
CVE-2026-71625Critical· 9.8PoC
2w ago

An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component

An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component

▾ AbyssalEPSS 0.40%via NVD
CVE-2026-71624Critical· 9.8PoC
2w ago

An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php, and core/lib/ET.class.php components

An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php, and core/lib/ET.class.php components

▾ AbyssalEPSS 0.52%via NVD
CVE-2026-50894Critical· 9.8PoC
2w ago

easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted fil…

easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted fil…

▾ AbyssalEPSS 0.48%via NVD
CVE-2026-44402Critical· 9.8PoC
2w ago

Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar arc…

Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar arc…

▾ AbyssalVoltronic Power · SNMP Web ProEPSS 0.89%via NVD
CVE-2026-11613Critical· 9.8PoC
2w ago

The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter

The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to inclu…

▾ AbyssalEPSS 0.46%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

Most-affected vendors

By CVEs published in the period.