VulnSea

Daily digest

Thursday 15 January 2026

A quiet day: only 15 new CVEs against a recent average of about 46. Of those, 1 critical and 6 high. 6 arrived with exploitation evidence or public exploit code already attached.

15
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 15 published.

CVE-2021-47785Critical· 9.8PoC
8mo ago

Ether_MP3_CD_Burner 1.3.8 - Buffer Overflow (SEH)

Ether MP3 CD Burner 1.3.8 contains a buffer overflow vulnerability in the registration name field that allows remote code execution. Attackers can craft a malicious payload to overwrite SEH handlers and execute a bind shell on port 3110 …

▾ AbyssalMp3-Avi-Mpeg-Wmv-Rm-To-Audio-Cd-Burner · Ether_MP3_CD_BurnerEPSS 0.92%via CVEORG
CVE-2021-47792High· 7.8PoC
8mo ago

Remote Mouse 4.002 - Unquoted Service Path

Remote Mouse 4.002 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the RemoteMouseService to inject…

▾ MidnightRemotemouse · Remote MouseEPSS 0.23%via CVEORG
CVE-2026-0897High· 7.5PoC
8mo ago

Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a c…

Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a c…

▾ Midnightkeras · kerasEPSS 0.34%via NVD
CVE-2025-13845High· 7.8
8mo ago

CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.

CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.

▾ Twilightschneider-electric · ecostruxure_power_build_-_rapsodyEPSS 0.35%via NVD
CVE-2021-47779Medium· 5.4PoC
8mo ago

Dolibarr ERP-CRM 14.0.2 - Stored Cross-Site Scripting (XSS) / Privilege Escalation

Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject malicious scripts. Attackers can craft a specially designed ticket message with embedded…

▾ TwilightDolibarr · CRMEPSS 0.36%via CVEORG
CVE-2021-47765Medium· 5.5PoC
8mo ago

AbsoluteTelnet 11.24 - 'Username' Denial of Service (PoC)

AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating username and error report fields. Attackers can trigger the crash by inserting 1000 characters into the …

▾ TwilightCelestialsoftware · AbsoluteTelnetEPSS 0.20%via CVEORG
CVE-2021-47764Medium· 5.5PoC
8mo ago

AbsoluteTelnet 11.24 - 'Phone' Denial of Service (PoC)

AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating DialUp connection and license name fields. Attackers can generate a 1000-character payload and paste it …

▾ TwilightCelestialsoftware · AbsoluteTelnetEPSS 0.20%via CVEORG
CVE-2026-23519High
8mo ago

RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`

RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`

▾ Twilightcmov · cmovEPSS 0.57%via OSV
CVE-2026-22775High· 7.5
8mo ago

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.1.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potenti…

▾ Twilightsvelte · devalueEPSS 0.64%via NVD
CVE-2026-22774High· 7.5
8mo ago

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.3.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potenti…

▾ Twilightsvelte · devalueEPSS 0.64%via NVD
CVE-2026-0990Medium· 5.9
8mo ago

A flaw was found in libxml2, an XML parsing library

A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker cou…

▾ SunlitEPSS 0.97%via NVD
CVE-2025-13844Medium· 5.3
8mo ago

CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.

CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.

▾ Sunlitschneider-electric · ecostruxure_power_build_-_rapsodyEPSS 0.16%via NVD

Most-affected vendors

By CVEs published in the period.