VulnSea

Daily digest

Friday 16 January 2026

A quiet day: only 9 new CVEs against a recent average of about 37. Severity skewed high: 7 high, 78% of the total. 2 arrived with exploitation evidence or public exploit code already attached.

9
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 9 that matter most of the 9 published.

CVE-2026-23490High· 7.5PoC
8mo ago

pyasn1 is a generic ASN.1 library for Python

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.

▾ Midnightpyasn1 · pyasn1EPSS 0.77%via NVD
CVE-2026-23745Medium· 6.1PoC
8mo ago

node-tar is a Tar for Node.js

node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass…

▾ Twilightisaacs · tarEPSS 0.38%via NVD
CVE-2026-23535High· 8.0
8mo ago

Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command

Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command

▾ Twilightwlc · wlcEPSS 0.39%via OSV
CVE-2021-47822High· 7.8
8mo ago

DiskBoss Service 12.2.18 - 'diskbsa.exe' Unquoted Service Path

DiskBoss Service 12.2.18 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path by placing malicious …

▾ TwilightDiskboss · DiskBoss ServiceEPSS 0.17%via CVEORG
CVE-2025-68675High· 7.5
8mo ago

Apache Airflow proxy credentials for various providers might leak in task logs

Apache Airflow proxy credentials for various providers might leak in task logs

▾ Twilightapache-airflow · apache-airflowEPSS 2.0%via OSV
CVE-2025-68438High· 7.5
8mo ago

Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated

Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated

▾ Twilightapache-airflow · apache-airflowEPSS 0.66%via OSV
CVE-2021-47814High· 7.5
8mo ago

NBMonitor 1.6.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the registration code input field

NBMonitor 1.6.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the registration code input field. Attackers can paste a 256-character buffer into the registration key field to tri…

▾ Twilightnsasoft · nbmonitorEPSS 0.42%via NVD
CVE-2021-47839High· 7.2
8mo ago

Marky 0.0.1 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files

Marky 0.0.1 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files. Attackers can upload crafted markdown files with embedded JavaScript payloads that execute when t…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-23528Medium
8mo ago

Dask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard

Dask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard

▾ Sunlitdistributed · distributedEPSS 0.24%via OSV

Most-affected vendors

By CVEs published in the period.