Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-45554Medium· 5.3NiceGUI: Unauthenticated log-volume denial of service in dynamic resource routes
CVE-2026-45553High· 7.5NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()
CVE-2026-39844Medium· 5.9NiceGUI: Upload filename sanitization bypass via backslashes allows path traversal on Windows
CVE-2026-33332Medium· 5.3NiceGUI's unvalidated chunk size parameter in media routes can cause memory exhaustion
CVE-2026-27156Medium· 6.1NiceGUI vulnerable to XSS via Code Injection during client-side element function execution
CVE-2026-25516Medium· 6.1NiceGUI's XSS vulnerability in ui.markdown() allows arbitrary JavaScript execution through unsanitized HTML content
CVE-2026-21874Medium· 5.3NiceGUI has Redis connection leak via tab storage causes service degradation
CVE-2026-21873High· 7.2NiceGUI apps which use `ui.sub_pages` vulnerable to zero-click XSS
CVE-2026-21872Medium· 6.1NiceGUI apps are vulnerable to XSS which uses `ui.sub_pages` and render arbitrary user-provided links
CVE-2026-21871Medium· 6.1NiceGUI is vulnerable to XSS via Unescaped URL in ui.navigate.history.push() / replace()
CVE-2025-66645High· 7.5NiceGUI has a path traversal in app.add_media_files() allows arbitrary file read
CVE-2025-66469Medium· 6.1NiceGUI Reflected XSS in ui.add_css, ui.add_scss, and ui.add_sass via Style Injection
CVE-2025-66470Medium· 6.1PoCNiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content
CVE-2025-53354Medium· 6.1NiceGUI has a Reflected XSS
CVE-2025-21618High· 7.5NiceGUI On Air authentication issue
CVE-2024-32005High· 8.2NiceGUI allows potential access to local file system
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.