Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-55227Medium· 4.3Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
CVE-2026-55228High· 8.1Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
CVE-2026-50127Medium· 5.9Weblate SSRF: outbound URL guard misses some private ranges
CVE-2026-45106Medium· 4.6Weblate: Stored HTML injection in editor search preview
CVE-2026-44263Medium· 4.3Weblate Vulnerable to Private Translation Enumeration via Screenshot API
CVE-2026-44264Medium· 4.3Weblate vulnerable to XSS via crafted Markdown
CVE-2026-41654MediumWeblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
CVE-2026-41519Medium· 4.2Weblate Doesn't Invalidate API Token on Password Change
CVE-2026-34244Medium· 5.0Weblate: SSRF via Project-Level Machinery Configuration
CVE-2026-33212Low· 3.1Weblate: Improper access control for pending tasks in API
CVE-2026-34242High· 7.7Weblate: Arbitrary File Read via Symlink
CVE-2026-40256Medium· 5.0Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
CVE-2026-33440Medium· 5.0Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
CVE-2026-27457Medium· 4.3Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
CVE-2026-24126Medium· 6.6PoCWeblate has an argument injection in management console
CVE-2026-21889LowWeblate leaks information via screenshots
CVE-2025-68279High· 7.7Weblate has an arbitrary file read via symbolic links
CVE-2025-64725LowWeblate has improper validation upon invitation acceptance
CVE-2025-61587Medium· 6.1Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL…
CVE-2025-58352LowWeblate has a long session expiry when verifying second factor
CVE-2025-47951Medium· 4.9Weblate lacks rate limiting when verifying second factor
CVE-2025-49134Medium· 5.3Weblate exposes personal IP address via e-mail
CVE-2024-39303Medium· 4.4Weblate vulnerable to improper sanitization of project backups
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.