VulnSea

Daily digest · in progress

Saturday 3 October 2026

A quiet day: only 11 new CVEs against a recent average of about 448 so far. Of those, 1 critical and 2 high.

11
New CVEs
1
Critical
0
KEV additions
3
Records changed

New this day, ranked by depth score

The 11 that matter most of the 11 published.

CVE-2026-105080Critical· 9.9
today

In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre

In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.

▾ MidnightC4illin · ConvertXvia NVD
CVE-2026-104433High· 7.5
today

Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame

Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attac…

▾ Twilightkvcache-ai · Mooncakevia NVD
CVE-2026-104478High· 7.1
today

Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files

Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded b…

▾ Twilightgetformwork · formworkvia NVD
CVE-2026-104474Medium· 6.7
today

OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root

OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace …

▾ Sunlitlitespeedtech · openlitespeedvia NVD
CVE-2026-104477Medium· 6.1
today

Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed into href and src attributes

Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed into href and src attributes. Attackers can craft markdown link…

▾ Sunlitshowdownjs · showdownvia NVD
CVE-2026-104476Medium· 5.9
today

Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer

Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives gen…

▾ Sunlitbackdrop · backdropvia NVD
CVE-2026-104479Medium· 5.4
today

Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled

Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled. Attackers can submit malicious Jav…

▾ Sunlitmindstellar · shopclassvia NVD
CVE-2026-104475Medium· 5.4
today

IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authenticated users to inject scripts by uploading unsanitized SVG files

IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authenticated users to inject scripts by uploading unsanitized SVG files. Attackers can upload JavaScript-laden SVGs via the profile update or …

▾ Sunlitidurar · idurar-erp-crmvia NVD
CVE-2026-105030Medium· 5.3
today

Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters

Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supp…

▾ Sunlitrajnandan1 · kenervia NVD
CVE-2026-79113Medium· 5.1
today

OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow.

OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow.

▾ Sunlitaswf · OpenAPVvia NVD
CVE-2026-105029Medium· 4.3
today

UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets

UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can …

▾ Sunlituvdesk · support-center-bundlevia NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-9901Envoy 1.9.0 and before does not normalize HTTP URL paths37
  • CVE-2025-71348Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config45
  • CVE-2014-6407Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.42

Most-affected vendors

By CVEs published in the period.