VulnSea

Daily digest

Saturday 12 September 2026

A quiet day: only 92 new CVEs against a recent average of about 537. Of those, 13 critical and 25 high. 22 arrived with exploitation evidence or public exploit code already attached. WWBN was the most-affected vendor with 17.

92
New CVEs
13
Critical
0
KEV additions
1117
Records changed

New this day, ranked by depth score

The 12 that matter most of the 92 published.

CVE-2026-85706Critical· 10.0CISA KEV0dayPoC
1w ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the Gi…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the Gi…

Hadalgitlab · gitlabEPSS 15%via NVD
MAL-2026-16142Critical⚠ Exploited
1w ago

Malicious code in python-fork (PyPI)

Malicious code in python-fork (PyPI)

Abyssalpython-fork · python-forkvia OSV
CVE-2026-78159Critical· 9.8PoC
1w ago

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a…

Abyssalstellarwp · The Events CalendarEPSS 0.76%via NVD
CVE-2026-78006Critical· 9.8PoC
1w ago

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance,…

Abyssalstellarwp · The Events CalendarEPSS 0.78%via NVD
CVE-2026-90560High· 8.2PoC
1w ago

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply …

MidnightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.34%via NVD
CVE-2026-90537High· 8.2PoC
1w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a…

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a…

MidnightWWBN · AVideoEPSS 0.21%via NVD
CVE-2026-89266High· 8.2PoC
1w ago

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimension…

Midnightnothings · stb_vorbisEPSS 0.47%via NVD
CVE-2026-87719Critical· 9.9
1w ago

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advance…

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advance…

MidnightGitLab · GitLabEPSS 0.61%via NVD
CVE-2026-82845Critical· 9.9
1w ago

The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of…

The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of…

MidnightEPSS 0.35%via NVD
CVE-2026-90558Critical· 9.8
1w ago

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or…

Midnightirontec · sngrepEPSS 0.51%via NVD
CVE-2026-85681Critical· 9.8
1w ago

The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allo…

The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allo…

MidnightEPSS 0.28%via NVD
CVE-2026-85200High· 7.5PoC
1w ago

The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function

The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to in…

Midnightninjew · GEO my WPEPSS 1.9%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-87491Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page74
  • CVE-2026-86060RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation79
  • CVE-2026-67277RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication70
  • CVE-2026-20079A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …95
  • CVE-2026-49881In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the code55
  • CVE-2026-52486An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument module48
  • CVE-2026-84869A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances80
  • CVE-2026-53758Emlog is an open source website building system60

Most-affected vendors

By CVEs published in the period.