VulnSea

Daily digest

Friday 2 January 2026

A busier-than-usual day with 32 new CVEs (recent average about 27). Severity skewed high: 3 critical and 17 high, 63% of the total. 2 arrived with exploitation evidence or public exploit code already attached. yonyou was the most-affected vendor with 7.

32
New CVEs
3
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 32 published.

CVE-2026-21445HighPoC
9mo ago

Langflow Missing Authentication on Critical API Endpoints

Langflow Missing Authentication on Critical API Endpoints

▾ Midnightlangflow-base · langflow-baseEPSS 33%via OSV
CVE-2025-67268Critical· 9.8
9mo ago

gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file

gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file. The hnd_129540 function, which handles NMEA2000 PGN 129540 (GNSS Satellites in View) packets, fails to validate the…

▾ Midnightgpsd_project · gpsdEPSS 0.79%via NVD
CVE-2025-64123Critical· 9.8
9mo ago

Unintended Proxy or Intermediary vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Network Boundary Bridging.This issue affects Multi-Stack Controller (MSC): through and including release 2.5.1.

Unintended Proxy or Intermediary vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Network Boundary Bridging.This issue affects Multi-Stack Controller (MSC): through and including release 2.5.1.

▾ Midnightnuvationenergy · nplatformEPSS 0.32%via NVD
CVE-2025-64121Critical· 9.8
9mo ago

Authentication Bypass Using an Alternate Path or Channel vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Authentication Bypass.This issue affects Multi-Stack Controller (MSC): from 2.3.8 before 2.5.1.

Authentication Bypass Using an Alternate Path or Channel vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Authentication Bypass.This issue affects Multi-Stack Controller (MSC): from 2.3.8 before 2.5.1.

▾ Midnightnuvationenergy · nplatformEPSS 0.40%via NVD
CVE-2025-64120High· 8.8
9mo ago

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows OS Command Injection.This issue affects Multi-Stack Controller (MSC): from 2.…

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows OS Command Injection.This issue affects Multi-Stack Controller (MSC): from 2.…

▾ Twilightnuvationenergy · nplatformEPSS 1.0%via NVD
CVE-2025-15431High· 8.8
9mo ago

A flaw has been found in UTT 进取 512W 1.7.7-171114

A flaw has been found in UTT 进取 512W 1.7.7-171114. This affects the function strcpy of the file /goform/formFtpServerDirConfig. Executing a manipulation of the argument filename can lead to buffer overflow. The attack can be launched rem…

▾ Twilightutt · 512w_firmwareEPSS 0.80%via NVD
CVE-2025-15430High· 8.8
9mo ago

A vulnerability was detected in UTT 进取 512W 1.7.7-171114

A vulnerability was detected in UTT 进取 512W 1.7.7-171114. Affected by this issue is the function strcpy of the file /goform/formFtpServerShareDirSelcet. Performing a manipulation of the argument oldfilename results in buffer overflow. Th…

▾ Twilightutt · 512w_firmwareEPSS 0.80%via NVD
CVE-2025-15429High· 8.8
9mo ago

A security vulnerability has been detected in UTT 进取 512W 1.7.7-171114

A security vulnerability has been detected in UTT 进取 512W 1.7.7-171114. Affected by this vulnerability is the function strcpy of the file /goform/formConfigCliForEngineerOnly. Such manipulation of the argument addCommand leads to buffer …

▾ Twilightutt · 512w_firmwareEPSS 0.88%via NVD
CVE-2025-15428High· 8.8
9mo ago

A weakness has been identified in UTT 进取 512W 1.7.7-171114

A weakness has been identified in UTT 进取 512W 1.7.7-171114. Affected is the function strcpy of the file /goform/formRemoteControl. This manipulation of the argument Profile causes buffer overflow. It is possible to initiate the attack re…

▾ Twilightutt · 512w_firmwareEPSS 0.88%via NVD
CVE-2025-69414High· 8.5
9mo ago

Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.

Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.

▾ Twilightplex · media_serverEPSS 0.25%via NVD
CVE-2025-62842High· 7.8
9mo ago

An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync

An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read or modify files or directories. We h…

▾ Twilightqnap · hybrid_backup_syncEPSS 0.27%via NVD
CVE-2025-67269High· 7.5
9mo ago

An integer underflow vulnerability exists in the `nextstate()` function in `gpsd/packet.c` of gpsd versions prior to commit `ffa1d6f40bca0b035fc7f5e563160ebb67199da7`

An integer underflow vulnerability exists in the `nextstate()` function in `gpsd/packet.c` of gpsd versions prior to commit `ffa1d6f40bca0b035fc7f5e563160ebb67199da7`. When parsing a NAVCOM packet, the payload length is calculated using …

▾ Twilightgpsd_project · gpsdEPSS 0.56%via NVD

Most-affected vendors

By CVEs published in the period.