VulnSea

Daily digest

Saturday 10 January 2026

A quiet day: only 8 new CVEs against a recent average of about 48. Severity skewed high: 1 critical and 3 high, 50% of the total. 2 arrived with exploitation evidence or public exploit code already attached. shopify was the most-affected vendor with 4.

8
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 8 that matter most of the 8 published.

CVE-2025-61686Critical· 9.1PoC
8mo ago

React Router is a router for React

React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if createFileSessionStorage() is being used from @react-router/…

▾ Abyssalshopify · react-router/nodeEPSS 18%via NVD
CVE-2025-59057High· 7.6PoC
8mo ago

React Router is a router for React

React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating s…

▾ Midnightshopify · react-routerEPSS 0.51%via NVD
CVE-2026-21884High· 8.2
8mo ago

React Router is a router for React

React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's <ScrollRestoration> API in Framework Mode when using the getKey/stora…

▾ Twilightshopify · react-routerEPSS 0.54%via NVD
CVE-2026-22029High· 8.0
8mo ago

React Router is a router for React

React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, D…

▾ Twilightshopify · remix-run/reactEPSS 0.88%via NVD
CVE-2026-22773Medium· 6.5
8mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users can crash the vLLM engine serving multimodal models that use the Idefics3 vision model implementation by sending a s…

▾ Sunlitvllm · vllmEPSS 0.45%via NVD
CVE-2026-22703Medium· 5.5
8mo ago

github.com/sigstore/cosign: Cosign verification accepts any valid Rekor entry under certain conditions (CVE-2026-22703)

A data verification flaw has been discovered in the golang cosign library. A Cosign bundle can be crafted to successfully verify an artifact even if the embedded Rekor entry does not reference the artifact's digest, signature or public key…

▾ SunlitRed Hat · OpenShift PipelinesEPSS 0.11%via CSAF
CVE-2026-22701Medium· 5.3
8mo ago

filelock: filelock Time-of-Check-Time-of-Use (TOCTOU) in SoftFileLock (CVE-2026-22701)

A Time-of-Check-Time-of-Use (TOCTOU) flaw has been discovered in the pypi filelock package. The TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access…

▾ SunlitRed Hat · Red Hat Ansible Automation Platform 2EPSS 0.13%via CSAF
CVE-2025-15504Low· 3.3
8mo ago

LIEF is vulnerable to segmentation fault

LIEF is vulnerable to segmentation fault

▾ Sunlitlief · liefEPSS 0.27%via OSV

Most-affected vendors

By CVEs published in the period.