Daily digest
Friday 16 January 2026
A quiet day: only 9 new CVEs against a recent average of about 37. Severity skewed high: 7 high, 78% of the total. 2 arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 9 that matter most of the 9 published.
CVE-2026-23490High· 7.5PoCpyasn1 is a generic ASN.1 library for Python
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.
CVE-2026-23745Medium· 6.1PoCnode-tar is a Tar for Node.js
node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass…
CVE-2026-23535High· 8.0Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command
Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command
CVE-2021-47822High· 7.8DiskBoss Service 12.2.18 - 'diskbsa.exe' Unquoted Service Path
DiskBoss Service 12.2.18 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path by placing malicious …
CVE-2025-68675High· 7.5Apache Airflow proxy credentials for various providers might leak in task logs
Apache Airflow proxy credentials for various providers might leak in task logs
CVE-2025-68438High· 7.5Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated
Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated
CVE-2021-47814High· 7.5NBMonitor 1.6.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the registration code input field
NBMonitor 1.6.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the registration code input field. Attackers can paste a 256-character buffer into the registration key field to tri…
CVE-2021-47839High· 7.2Marky 0.0.1 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files
Marky 0.0.1 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files. Attackers can upload crafted markdown files with embedded JavaScript payloads that execute when t…
CVE-2026-23528MediumDask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard
Dask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard
Most-affected vendors
By CVEs published in the period.