VulnSea

Daily digest

Wednesday 14 January 2026

A quiet day: only 20 new CVEs against a recent average of about 54. Of those, 4 critical and 4 high. Linux was the most-affected vendor with 8.

20
New CVEs
4
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 20 published.

CVE-2026-22853Critical· 9.8
8mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated from hints, causing a …

▾ Midnightfreerdp · freerdpEPSS 0.76%via NVD
CVE-2026-22859Critical· 9.1
8mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑supplied MSUSB_INTERFACE_DESCRIPTOR values and uses them as indices in libusb_udev_complete_ms…

▾ Midnightfreerdp · freerdpEPSS 0.87%via NVD
CVE-2026-22858Critical· 9.1
8mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding path. The root cause appears to be implementation-defined char signedness: on Arm/AArch64 …

▾ Midnightfreerdp · freerdpEPSS 0.69%via NVD
CVE-2026-22855Critical· 9.1
8mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-bounds read occurs in the smartcard SetAttrib path when cbAttrLen does not match the actual NDR buffer length. This vulnerability is fixed in…

▾ Midnightfreerdp · freerdpEPSS 0.87%via NVD
CVE-2025-71112High· 8.8
8mo ago

net: hns3: add VLAN id validation before using

In the Linux kernel, the following vulnerability has been resolved: net: hns3: add VLAN id validation before using Currently, the VLAN id may be used without validation when receive a VLAN configuration mailbox from VF. The length of v…

▾ TwilightLinux · LinuxEPSS 0.15%via CVEORG
CVE-2026-0532High· 8.6
8mo ago

External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connect…

External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connect…

▾ TwilightRed Hat · Red Hat OpenShift distributed tracing 3EPSS 0.48%via NVD
CVE-2025-71131High· 7.5
8mo ago

crypto: seqiv - Do not use req->iv after crypto_aead_encrypt

In the Linux kernel, the following vulnerability has been resolved: crypto: seqiv - Do not use req->iv after crypto_aead_encrypt As soon as crypto_aead_encrypt is called, the underlying request may be freed by an asynchronous completio…

▾ TwilightLinux · LinuxEPSS 0.28%via CVEORG
CVE-2025-71120High· 7.5
8mo ago

SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf A zero length gss_token results in pages == 0 and in_token->pages[0] is NULL. The…

▾ TwilightLinux · LinuxEPSS 0.48%via CVEORG
CVE-2025-65397Medium· 6.8
8mo ago

An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows an attacker with physical access to the device to execute arbitrary commands with root privileges,…

An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows an attacker with physical access to the device to execute arbitrary commands with root privileges,…

▾ Sunlitblurams · dome_flare_firmwareEPSS 0.32%via NVD
CVE-2025-14242Medium· 6.5
8mo ago

A flaw was found in vsftpd

A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated attacker sending a crafted STAT command with a specific byt…

▾ SunlitEPSS 0.82%via NVD
CVE-2025-65396Medium· 6.1
8mo ago

A vulnerability in the boot process of Blurams Flare Camera version 24.1114.151.929 and earlier allows a physically proximate attacker to hijack the boot mechanism and gain a bootloader shell via the UART interface

A vulnerability in the boot process of Blurams Flare Camera version 24.1114.151.929 and earlier allows a physically proximate attacker to hijack the boot mechanism and gain a bootloader shell via the UART interface. This is achieved by i…

▾ Sunlitblurams · dome_flare_firmwareEPSS 0.21%via NVD
CVE-2026-22779Medium
8mo ago

BlackSheep's ClientSession is vulnerable to CRLF injection

BlackSheep's ClientSession is vulnerable to CRLF injection

▾ Sunlitblacksheep · blacksheepEPSS 0.36%via OSV

Most-affected vendors

By CVEs published in the period.