VulnSea

Daily digest · in progress

Friday 2 October 2026

A quiet day: only 11 new CVEs against a recent average of about 466 so far. Severity skewed high: 4 critical and 4 high, 73% of the total. GeoVision Inc. was the most-affected vendor with 3.

11
New CVEs
4
Critical
0
KEV additions
3
Records changed

New this day, ranked by depth score

The 11 that matter most of the 11 published.

CVE-2026-103764Critical· 9.8
today

Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port

Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can…

▾ Midnightkvcache-ai · Mooncakevia NVD
CVE-2026-104480Critical· 9.4
today

Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership

Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position abl…

▾ MidnightDiscord · discord/libdavevia CVEORG
CVE-2026-103765Critical· 9.4
today

Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys

Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can…

▾ Midnightkvcache-ai · Mooncakevia NVD
CVE-2026-86345Critical· 9.0
today

A flaw was found in 389-ds-base

A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the T…

▾ MidnightRed Hat · 389-ds-basevia NVD
CVE-2026-103098High· 7.5
today

Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network

Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor net…

▾ TwilightGeoVision Inc. · tw.com.geovision.gveyevia NVD
CVE-2026-103097High· 7.5
today

An API key is hardcoded and retrievable from the application package

An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract an…

▾ TwilightGeoVision Inc. · tw.com.geovision.gveyevia NVD
CVE-2026-103096High· 7.5
today

API key is hardcoded and retrievable from the application package

API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and m…

▾ TwilightGeoVision Inc. · tw.com.geovision.gveyevia NVD
CVE-2026-103766High· 7.2
today

ClipBucket v5 through 5.5.3-#197 contains an sql injection vulnerability that allows authenticated users with ad_manager_access permission to inject SQL via the delete parameter in admin_area/ads_manager.php

ClipBucket v5 through 5.5.3-#197 contains an sql injection vulnerability that allows authenticated users with ad_manager_access permission to inject SQL via the delete parameter in admin_area/ads_manager.php. Attackers can supply time-ba…

▾ TwilightMacWarrior · clipbucket-v5via NVD
CVE-2026-21140Medium· 6.9
today

Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.

Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.

▾ SunlitSamsung Mobile · Samsung Mobile Devicesvia CVEORG
CVE-2026-104053Medium· 6.3
today

itsourcecode Pet Shop Management System admin_reservefilter.php sql injection

A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql injection. It is possib…

▾ Sunlititsourcecode · Pet Shop Management Systemvia CVEORG
CVE-2026-104052Medium· 6.3
today

itsourcecode Pet Shop Management System admin_reject_completed.php sql injection

A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injection. It is possible …

▾ Sunlititsourcecode · Pet Shop Management Systemvia CVEORG

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-9901EnvoyProxy Envoy Missing HTTP URL path normalization56
  • CVE-2025-71348picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods57
  • CVE-2014-6407Arbitrary Code Execution in Docker41

Most-affected vendors

By CVEs published in the period.