VulnSea

Daily digest

Sunday 6 September 2026

92 new CVEs this day, in line with the recent average. Severity skewed high: 13 critical and 37 high, 54% of the total. 59 arrived with exploitation evidence or public exploit code already attached. SourceCodester was the most-affected vendor with 13.

92
New CVEs
13
Critical
0
KEV additions
2
Records changed

New this day, ranked by depth score

The 12 that matter most of the 92 published.

CVE-2026-86218Critical· 9.8CISA KEVPoC
2w ago

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

▾ Hadaln-able · n-centralEPSS 7.5%via NVD
MAL-2026-15938Critical⚠ Exploited
2w ago

Malicious code in dac-tools (PyPI)

Malicious code in dac-tools (PyPI)

▾ Abyssaldac-tools · dac-toolsvia OSV
CVE-2026-86167Critical· 9.9PoC
2w ago

A vulnerability was identified in Tenda HG10 300001138

A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remot…

▾ AbyssalTenda · HG10EPSS 1.6%via NVD
CVE-2026-86165Critical· 9.8PoC
2w ago

A vulnerability was found in Tenda HG10 300001138

A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be …

▾ AbyssalTenda · HG10EPSS 0.64%via NVD
CVE-2026-75816Critical· 9.8PoC
2w ago

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or owners…

▾ AbyssalEPSS 0.50%via NVD
CVE-2026-19931Critical· 9.8PoC⚖ disputed
2w ago

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previo…

▾ Abyssalhaxx · curlEPSS 1.2%via NVD
CVE-2026-86151Critical· 9.1PoC
2w ago

A vulnerability was detected in Tenda CP3 27.5.57.101

A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection…

▾ AbyssalTenda · CP3EPSS 2.0%via NVD
CVE-2026-18924Critical· 9.1PoC⚖ disputed
2w ago

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

▾ Abyssalhaxx · curlEPSS 0.90%via NVD
CVE-2026-86166High· 8.8PoC
2w ago

A vulnerability was determined in Tenda HG10 300001138

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer …

▾ MidnightTenda · HG10EPSS 0.48%via NVD
CVE-2026-82209High· 8.2PoC⚖ disputed
2w ago

When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Do…

When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Do…

▾ Midnighthaxx · curlEPSS 0.54%via NVD
CVE-2026-86152Critical· 10.0
2w ago

A flaw has been found in Tenda CP3 27.5.57.101

A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The at…

▾ MidnightTenda · CP3EPSS 1.9%via NVD
CVE-2026-86304Critical· 9.8
2w ago

MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor. parse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAM…

MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor. parse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAM…

▾ MidnightEPSS 0.22%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2017-8046Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbi…87
  • CVE-2018-0101A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute c…84

Most-affected vendors

By CVEs published in the period.