VulnSea

Daily digest · in progress

Sunday 4 October 2026

A quiet day: only 11 new CVEs against a recent average of about 374 so far. Of those, 2 high. laradashboard was the most-affected vendor with 6.

11
New CVEs
0
Critical
0
KEV additions
3
Records changed

New this day, ranked by depth score

The 11 that matter most of the 11 published.

CVE-2026-105123High· 8.8
today

W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]

W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload…

▾ Twilightvincent-peugnet · wcmsvia NVD
CVE-2026-105126High· 7.2
today

LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles

LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin…

▾ Twilightlaradashboard · laradashboardvia NVD
CVE-2026-105129Medium· 6.5
today

LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API

LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /ap…

▾ Sunlitlaradashboard · laradashboardvia NVD
CVE-2026-105096Medium· 6.3
today

A vulnerability was determined in Omega Solution CoinEx Crypto 2025

A vulnerability was determined in Omega Solution CoinEx Crypto 2025. This affects an unknown function of the file /customer/ of the component Customer Profile API. Executing a manipulation of the argument ID can lead to authorization byp…

▾ SunlitOmega Solution · CoinEx Cryptovia NVD
CVE-2026-105124Medium· 6.1
today

W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field

W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed …

▾ Sunlitvincent-peugnet · wcmsvia NVD
CVE-2026-105131Medium· 5.4
today

ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json

ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. Because TokenRefreshHandler never checks token type…

▾ Sunlitmayswind · ezBookkeepingvia NVD
CVE-2026-105128Medium· 5.4
today

LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit

LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send c…

▾ Sunlitlaradashboard · laradashboardvia NVD
CVE-2026-105127Medium· 5.3
today

LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls

LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbit…

▾ Sunlitlaradashboard · laradashboardvia NVD
CVE-2026-105097Medium· 4.3
today

Omega Solution CoinEx Crypto Customer Information API customer-currency authorization

A vulnerability was identified in Omega Solution CoinEx Crypto 2025. This impacts an unknown function of the file /customer-currency/ of the component Customer Information API. The manipulation of the argument ID leads to authorization b…

▾ SunlitOmega Solution · CoinEx Cryptovia CVEORG
CVE-2026-105130Low· 3.7
today

LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit

LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. Attackers can send many concurrent registr…

▾ Sunlitlaradashboard · laradashboardvia NVD
CVE-2026-105125Low· 3.7
today

LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment

LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences li…

▾ Sunlitlaradashboard · laradashboardvia NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-9901Envoy 1.9.0 and before does not normalize HTTP URL paths37
  • CVE-2025-71348Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config45
  • CVE-2014-6407Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.42

Most-affected vendors

By CVEs published in the period.