VulnSea

Daily digest

Tuesday 15 September 2026

A heavy day: 1,430 new CVEs, well above the recent average of about 583. Severity skewed high: 176 critical and 830 high, 70% of the total. 159 arrived with exploitation evidence or public exploit code already attached. Oracle Corporation was the most-affected vendor with 566.

1430
New CVEs
176
Critical
0
KEV additions
672
Records changed

New this day, ranked by depth score

The 12 that matter most of the 1430 published.

CVE-2026-19773Critical· 9.80day
6d ago

libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of libwebsockets. Authentication is no…

Hadallibwebsockets · libwebsocketsEPSS 0.65%via NVD
CVE-2026-19780High· 8.80day
6d ago

Koha Eval Code Injection Remote Code Execution Vulnerability

Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerability. The specific…

AbyssalKoha · KohaEPSS 0.96%via NVD
CVE-2026-58704High· 8.8CISA KEV0dayPoC
6d ago

In Cellular Modem, there is a possible permission bypass due to a logic error in the code

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not need…

Abyssalgoogle · androidEPSS 0.21%via NVD
CVE-2026-92180High· 7.80day
6d ago

pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PD…

Abyssalpdfforge · PDF ArchitectEPSS 0.14%via NVD
CVE-2026-92179High· 7.80day
6d ago

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction i…

Abyssalpdfforge · PDF ArchitectEPSS 0.17%via NVD
CVE-2026-92178High· 7.80day
6d ago

pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability

pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is …

Abyssalpdfforge · PDF ArchitectEPSS 0.17%via NVD
CVE-2026-92177High· 7.80day
6d ago

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction i…

Abyssalpdfforge · PDF ArchitectEPSS 0.17%via NVD
CVE-2026-92176High· 7.80day
6d ago

pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability

pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is requi…

Abyssalpdfforge · PDF ArchitectEPSS 0.17%via NVD
CVE-2026-19886High· 7.80day
6d ago

OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability

OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction i…

AbyssalOriginLab · Origin ViewerEPSS 0.17%via NVD
CVE-2026-19885High· 7.80day
6d ago

OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interactio…

AbyssalOriginLab · Origin ViewerEPSS 0.17%via NVD
CVE-2026-19781High· 7.80day
6d ago

Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction…

AbyssalAshlar-Vellum · CobaltEPSS 0.17%via NVD
CVE-2026-91998Critical· 9.9PoC
6d ago

Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizati…

Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizati…

Abyssalcasdoor · casdoorEPSS 0.42%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-9901EnvoyProxy Envoy Missing HTTP URL path normalization56
  • CVE-2014-6407Arbitrary Code Execution in Docker41
  • CVE-2025-71348picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods57
  • CVE-2026-52296FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.16
  • CVE-2026-10536A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates…66
  • CVE-2026-11856Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongl…66
  • CVE-2026-8925The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.66
  • CVE-2026-9079libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.66

Most-affected vendors

By CVEs published in the period.