Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-53495Medium· 6.8containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go …
CVE-2026-47262Mediumcontainerd image-triggered runtime DoS via unbounded group parsing
CVE-2026-50195Mediumcontainerd: CRI checkpoint import allows local image tag poisoning
CVE-2021-21334Medium· 6.3containerd environment variable leak
GHSA-7ww5-4wqc-m92cMediumcontainerd allows RAPL to be accessible to a container
CVE-2022-23471Medium· 5.7containerd CRI stream server vulnerable to host memory exhaustion via terminal
CVE-2022-31030Medium· 5.5containerd CRI plugin: Host memory exhaustion through ExecSync
CVE-2020-15157Medium· 6.1containerd v1.2.x can be coerced into leaking credentials during image pull
CVE-2021-43816High· 8.0Unprivileged pod using `hostPath` can side-step active LSM when it is SELinux
GHSA-5j5w-g665-5m35Low· 3.0Ambiguous OCI manifest parsing
CVE-2021-41103Medium· 5.9Insufficiently restricted permissions on plugin directories
CVE-2020-15257Medium· 5.2PoCcontainerd-shim API Exposed to Host Network Containers
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.