Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-46561Medium· 5.0pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API
CVE-2026-45306Medium· 6.5pyLoad Has Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory in pyLoad
CVE-2026-45348High· 8.7pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal
CVE-2026-44226Medium· 5.3PyLoad vulnerable to unauthenticated traceback disclosure via global exception handler in WebUI
CVE-2026-41133High· 8.8pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)
CVE-2026-40071Medium· 5.4pyload-ng has a WebUI JSON permission mismatch that lets ADD/DELETE users invoke MODIFY-only actions
CVE-2026-35463High· 8.8pyLoad: Improper Neutralization of Special Elements used in an OS Command
CVE-2026-35187High· 7.7pyLoad: SSRF in parse_urls API endpoint via unvalidated URL parameter
CVE-2026-35464High· 7.5pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for CVE-2026-33509)
CVE-2026-33509High· 7.5pyLoad SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script Configuration
CVE-2025-61773High· 8.1pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters
CVE-2025-57751HighDenial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs
CVE-2025-55156HighPyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter
CVE-2025-54802Critical· 9.8pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)
CVE-2025-54140High· 7.5`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write
CVE-2025-53890Critical· 9.8pyLoad vulnerable to XSS through insecure CAPTCHA
CVE-2025-7346High· 7.5pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages
CVE-2024-32880Critical· 9.1pyLoad allows upload to arbitrary folder lead to RCE
CVE-2024-24808Medium· 6.1pyLoad open redirect vulnerability due to improper validation of the is_safe_url function
CVE-2024-22416Critical· 9.6PoCCross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation
CVE-2024-21644High· 7.5PoCpyload Unauthenticated Flask Configuration Leakage vulnerability
CVE-2024-21645Medium· 5.3PoCpyload Log Injection vulnerability
CVE-2023-47890High· 7.6Download to arbitrary folder can lead to RCE
CVE-2023-0488Medium· 5.4Cross-site Scripting in pyload-ng
CVE-2023-0509High· 7.4Improper Certificate Validation in pyload-ng
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.