VulnSea

Daily digest

Sunday 13 September 2026

A quiet day: only 133 new CVEs against a recent average of about 498. Of those, 2 critical and 46 high. 74 arrived with exploitation evidence or public exploit code already attached. jaychouchannel was the most-affected vendor with 5.

133
New CVEs
2
Critical
0
KEV additions
1122
Records changed

New this day, ranked by depth score

The 12 that matter most of the 133 published.

MAL-2026-16143Critical⚠ Exploited
1w ago

Malicious code in chroma-client (PyPI)

Malicious code in chroma-client (PyPI)

Abyssalchroma-client · chroma-clientvia OSV
CVE-2026-81648Critical· 10.0PoC
1w ago

The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on …

The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on …

AbyssalEPSS 0.28%via NVD
CVE-2026-90777High· 8.8PoC
1w ago

ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files

ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code dur…

Midnightespnet · espnetEPSS 0.51%via NVD
CVE-2026-90493High· 8.8PoC
1w ago

A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows

A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper acces…

MidnightTonec · Internet Download ManagerEPSS 0.11%via NVD
CVE-2026-90510High· 8.3PoC
1w ago

A security vulnerability has been detected in dromara orion-visor up to 2.5.7

A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/jav…

Midnightdromara · orion-visorEPSS 0.29%via NVD
CVE-2026-90562High· 8.1PoC
1w ago

LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint

LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace t…

Midnightlangbot-app · LangBotEPSS 0.42%via NVD
CVE-2026-37008High· 8.1PoC
1w ago

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's co…

MidnightCrewAI · CrewAIEPSS 0.13%via NVD
CVE-2026-90772High· 7.6PoC
1w ago

Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components

Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerro…

Midnightamundsen-io · amundsen-frontendEPSS 0.21%via NVD
CVE-2026-90769High· 7.7PoC
1w ago

Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services

Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata,…

Midnightlfnovo · open-notebookEPSS 0.26%via NVD
CVE-2026-90776High· 7.5PoC
1w ago

Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments

Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separ…

Midnightnodemailer · nodemailerEPSS 0.48%via NVD
CVE-2026-90774High· 7.5PoC
1w ago

rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks

rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header …

Midnightorhun · rustypasteEPSS 0.38%via NVD
CVE-2026-90601High· 7.3PoC
1w ago

A vulnerability was found in getzep graphiti up to 0.30.2

A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launche…

Midnightgetzep · graphitiEPSS 0.41%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-87491Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page74
  • CVE-2026-67277RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication70
  • CVE-2026-86060RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation79
  • CVE-2026-20079A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …95
  • CVE-2026-53758Emlog is an open source website building system60
  • CVE-2026-49881In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the code55
  • CVE-2026-79570mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data66
  • CVE-2026-79574An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.66

Most-affected vendors

By CVEs published in the period.