VulnSea

Daily digest · in progress

Friday 25 September 2026

451 new CVEs this day, in line with the recent average so far. Of those, 4 critical and 28 high. One arrived with exploitation evidence or public exploit code already attached. Linux was the most-affected vendor with 359.

451
New CVEs
4
Critical
0
KEV additions
190
Records changed

New this day, ranked by depth score

The 12 that matter most of the 451 published.

MAL-2026-17180Critical⚠ Exploited
today

Malicious code in my-private-pkg (PyPI)

Malicious code in my-private-pkg (PyPI)

▾ Abyssalmy-private-pkg · my-private-pkgvia OSV
CVE-2026-14281Critical· 9.8
today

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcem…

▾ Midnight101gen · Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Codevia NVD
CVE-2026-93399Critical· 9.1
today

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX ac…

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX ac…

▾ Midnightladela · Online Scheduling and Appointment Booking System – Booklyvia NVD
CVE-2026-89055Critical· 9.1
today

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an actio…

▾ Midnightivole · Customer Reviews for WooCommercevia NVD
CVE-2026-89426High· 8.8
today

The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.6.1.0

The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.6.1.0. This is due to the `maybe_update_user_role()` function reading the ta…

▾ Twilightknitpay · Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and morevia NVD
CVE-2026-62062High· 8.8
today

Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1.

Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1.

▾ TwilightElementor · elementorvia NVD
CVE-2026-19804High· 8.8
today

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 260814 via the 'first_nam…

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 260814 via the 'first_nam…

▾ Twilightclavaque · s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptionsvia NVD
CVE-2026-97818High· 8.6
today

phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.

phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.

▾ Twilightphpipam · phpIPAMvia NVD
CVE-2026-97730High· 8.5
today

In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code

In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To ex…

▾ TwilightNetgate · pfSense Plusvia NVD
CVE-2026-85082High· 8.5
today

Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely separating the filename from the command.

Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely separating the filename from the command.

▾ TwilightMaple Media · Root Browser Classicvia NVD
CVE-2026-97898High· 8.4
today

Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service

Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unlock action is relying on a client-supplied room/door identifier that is not properly authorized server-side against the…

▾ Twilightakia · akiavia NVD
CVE-2026-97875High· 8.1
today

Rojo's "rojo serve" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding

Rojo's "rojo serve" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding. A malicious webpage can read all project source, write malicious code to files on disk, and launch local progr…

▾ Twilightrojo-rbx · rojovia NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-9901Envoy 1.9.0 and before does not normalize HTTP URL paths37
  • CVE-2025-71348Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config45
  • CVE-2014-6407Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.42
  • CVE-2026-53359In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a sha…55
  • CVE-2026-93207In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry svcauth_gss_decode_credbody() writes the caller's rpc_gss_wire_cred field by field and assigns gc…54
  • CVE-2026-97413In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Fix integer underflow in process_read and process_write usr_len is read from a network-supplied message field (le16_to_cpu) and used to compute data_len…54
  • CVE-2026-93228In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject Write/Reply chunks with segcount 0 A peer can send a Write or Reply chunk whose segcount field is zero. xdr_check_write_chunk() only rejects segcount >…50
  • CVE-2026-41140poetry: Poetry: Path traversal vulnerability allows arbitrary file write via malicious package extraction (CVE-2026-41140)48

Most-affected vendors

By CVEs published in the period.