VulnSea

Daily digest

Saturday 19 September 2026

A quiet day: only 109 new CVEs against a recent average of about 706. Of those, 9 critical and 23 high. 10 arrived with exploitation evidence or public exploit code already attached. Exim was the most-affected vendor with 4.

109
New CVEs
9
Critical
0
KEV additions
66
Records changed

New this day, ranked by depth score

The 12 that matter most of the 109 published.

MAL-2026-16298Critical⚠ Exploited
2d ago

Malicious code in urc (PyPI)

Malicious code in urc (PyPI)

Abyssalurc · urcvia OSV
CVE-2026-93985Critical· 9.9PoC
2d ago

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can c…

AbyssalOpenpanel-dev · openpanelEPSS 0.48%via NVD
CVE-2026-84434Critical· 9.8PoC
2d ago

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persis…

AbyssalGravity Forms · Gravity FormsEPSS 0.70%via NVD
CVE-2026-92229Critical· 9.1PoC
2d ago

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to e…

Abyssalwpmudev · Forminator Forms – Contact Form, Payment Form & Custom Form BuilderEPSS 0.40%via NVD
CVE-2026-89274Critical· 9.1PoC
2d ago

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()…

Abyssalbrechtvds · WP Recipe MakerEPSS 0.38%via NVD
CVE-2026-93993High· 8.8PoC
2d ago

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes…

Midnightmistralai · mistral-vibeEPSS 0.60%via NVD
CVE-2026-93923High· 8.8PoC
2d ago

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject maliciou…

Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.41%via NVD
CVE-2026-93742Critical· 9.9
2d ago

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be init…

MidnightTotolink · A3002MUEPSS 1.9%via NVD
CVE-2026-93741Critical· 10.0
2d ago

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It…

MidnightTotolink · A3002MUEPSS 0.64%via NVD
CVE-2026-86591Critical· 9.8
2d ago

The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege e…

The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege e…

MidnightEPSS 0.37%via NVD
CVE-2026-78030Critical· 9.8
2d ago

DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a mo…

DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a mo…

MidnightEPSS 0.73%via NVD
CVE-2026-93922High· 8.8
2d ago

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that exec…

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.54%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-9901EnvoyProxy Envoy Missing HTTP URL path normalization56
  • CVE-2014-6407Arbitrary Code Execution in Docker41
  • CVE-2025-71348picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods57
  • CVE-2026-52483The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(WVK.0)b46 allow authenticated users execute arbitrary OS command via concatenated params on a crafted POST request fo…60
  • CVE-2024-27304pgx: SQL Injection via Protocol Message Size Overflow (CVE-2024-27304)57
  • CVE-2026-86591The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege e…54
  • CVE-2026-85680The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allo…48
  • CVE-2026-88824The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Store…48

Most-affected vendors

By CVEs published in the period.