VulnSea

Weekly digest · in progress

Week 40, 2026 (28 Sep – 4 Oct)

A quiet week: only 6 new CVEs against a recent average of about 2,242 so far. Severity skewed high: 3 high, 50% of the total. Trusted Domain Project was the most-affected vendor with 4.

6
New CVEs
0
Critical
0
KEV additions
5
Records changed

New this week, ranked by depth score

The 6 that matter most of the 6 published.

CVE-2026-100891High· 7.3
today

Trusted Domain Project OpenDMARC Internationalized Domain Name opendmarc_policy.c opendmarc_policy_query_dmarc encoding error

A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of the component Internationalized Domain …

▾ TwilightTrusted Domain Project · OpenDMARCvia CVEORG
CVE-2026-100889High· 7.3
today

A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0

A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from r…

▾ TwilightTrusted Domain Project · OpenDKIMvia NVD
CVE-2026-100888High· 7.3
today

A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0

A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the function dkim_canon_selecthdrs of the file libopendkim/dkim-canon.c of the component DKIM Signature Header Selection. Executing a manipulati…

▾ TwilightTrusted Domain Project · OpenDKIMvia NVD
CVE-2026-100887Medium· 6.3
today

A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System up to 81bf0b55f5933f3b0dbb1583204a612e06605b95

A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. The impacted element is the function order_by of the file DB_query_builder.php of the component D…

▾ Sunlitamirsanni · Mini-Inventory-and-Sales-Management-Systemvia NVD
CVE-2026-100892Medium· 5.3
today

aligungr UERANSIM nr-gnb handler.cpp ULInformationTransfer memory corruption

A vulnerability was found in aligungr UERANSIM up to 3.3.0. This affects the function ULInformationTransfer of the file src/gnb/rrc/handler.cpp of the component nr-gnb. Performing a manipulation of the argument dedicatedNASMessage result…

▾ Sunlitaligungr · UERANSIMvia CVEORG
CVE-2026-100890Medium· 5.3
today

Trusted Domain Project OpenDMARC SPF Parser opendmarc_spf.c opendmarc_spf_ipv6_explode null pointer dereference

A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_spf_ipv6_explode in the library libopendmarc/opendmarc_spf.c of the component SPF Parser. This manipulation o…

▾ SunlitTrusted Domain Project · OpenDMARCvia CVEORG

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-9901Envoy 1.9.0 and before does not normalize HTTP URL paths37
  • CVE-2025-71348picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods57
  • CVE-2014-6407Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.42
  • CVE-2026-88771Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 1…77
  • CVE-2026-88772Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-…77

Most-affected vendors

By CVEs published in the period.