Daily digest
Sunday 11 January 2026
A quiet day: only 2 new CVEs against a recent average of about 45. Severity skewed high: 1 high, 50% of the total. One arrived with exploitation evidence or public exploit code already attached.
2
New CVEs
0
Critical
0
KEV additions
0
Records changed
New this day, ranked by depth score
The 2 that matter most of the 2 published.
CVE-2025-68493High· 8.1PoCMissing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes th…
Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes th…
▾ Midnightapache · strutsEPSS 46%via NVD
CVE-2025-15506Low· 3.3AcademySoftwareFoundation OpenColorIO has an out-of-bounds vulnerability
AcademySoftwareFoundation OpenColorIO has an out-of-bounds vulnerability
▾ Sunlitopencolorio · opencolorioEPSS 0.18%via OSV
Most-affected vendors
By CVEs published in the period.