VulnSea

Daily digest

Sunday 20 September 2026

A quiet day: only 102 new CVEs against a recent average of about 629. Of those, 9 critical and 30 high. 13 arrived with exploitation evidence or public exploit code already attached. SourceCodester was the most-affected vendor with 10.

102
New CVEs
9
Critical
0
KEV additions
142
Records changed

New this day, ranked by depth score

The 12 that matter most of the 102 published.

CVE-2026-90817Critical· 9.8PoC
yesterday

An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an uninte…

An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an uninte…

AbyssalVanderbilt University · REDCapEPSS 0.57%via NVD
CVE-2026-88854Critical· 9.3PoC
yesterday

Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with …

Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with …

AbyssalOrdaSoft.com · com_osgallery_lightEPSS 0.34%via NVD
CVE-2026-93958Critical· 9.1PoC
yesterday

A vulnerability was found in D-Link R95 BE9500_1.00.16

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack c…

AbyssalD-Link · R95EPSS 2.2%via NVD
CVE-2026-94036High· 8.8PoC
yesterday

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results…

MidnightD-Link · DIR-X1860EPSS 0.47%via NVD
CVE-2026-94089Critical· 10.0
yesterday

A vulnerability was determined in D-Link DIR-868L 2.01b05

A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lea…

MidnightD-Link · DIR-868LEPSS 0.98%via NVD
CVE-2026-94003Critical· 10.0
yesterday

A vulnerability has been found in Comfast CF-N1-S 2.6.0.1

A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. …

MidnightComfast · CF-N1-SEPSS 0.61%via NVD
CVE-2026-94084Critical· 9.4
yesterday

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

MidnightOISF · SuricataEPSS 0.40%via NVD
CVE-2026-94083Critical· 9.4
yesterday

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade)

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). Thi…

MidnightOISF · SuricataEPSS 0.40%via NVD
CVE-2026-94004High· 7.3PoC
yesterday

A vulnerability was found in DedeCMS up to 5.7.118

A vulnerability was found in DedeCMS up to 5.7.118. The affected element is an unknown function of the file plus/mytag_js.php. The manipulation of the argument aid results in code injection. The attack can be launched remotely. The explo…

MidnightEPSS 0.30%via NVD
CVE-2026-88857Critical· 9.4
yesterday

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the …

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the …

MidnightOrdaSoft.com · com_osgallery_lightEPSS 0.47%via NVD
CVE-2026-88856Critical· 9.4
yesterday

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_osgallery, read a JSON request body and…

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_osgallery, read a JSON request body and…

MidnightOrdaSoft.com · com_osgallery_lightEPSS 0.48%via NVD
CVE-2026-94109High· 8.8
yesterday

openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration

openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration. Authenticated attackers can inject malicious template expres…

Twilightopenequella · openEQUELLAEPSS 0.92%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-9901EnvoyProxy Envoy Missing HTTP URL path normalization56
  • CVE-2025-71348picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods57
  • CVE-2014-6407Arbitrary Code Execution in Docker41
  • CVE-2026-81000kernel: net: tun: bound receive headroom (CVE-2026-81000)55
  • CVE-2026-78030DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a mo…54
  • CVE-2026-92018Sandbox escape in the DOM: Core & HTML component53
  • CVE-2026-92040Use-after-free in the JavaScript: WebAssembly component48
  • CVE-2026-92046Use-after-free in the Graphics component48

Most-affected vendors

By CVEs published in the period.