Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-65315High· 7.5Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying a crafted GGUF file with attacker-controlled length and count fields…
CVE-2026-15685High· 7.50dayOllama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not require…
CVE-2026-7482Critical· 9.1PoCOllama contains a heap out-of-bounds read vulnerability in the GGUF model loader
CVE-2026-7020Medium· 5.6PoCOllama is Vulnerable to Path Traversal
CVE-2025-15514High· 7.5PoCOllama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality. When processing base64-encoded image data via the /api/chat endpoint, the applicat…
CVE-2025-63389CriticalOllama Platform has missing authentication enabling attackers to perform model management operations
CVE-2024-8063High· 7.5Ollama Divide by Zero Vulnerability
CVE-2024-28224High· 8.8Ollama DNS rebinding vulnerability
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.