VulnSea

Daily digest

Wednesday 21 January 2026

16 new CVEs this day, in line with the recent average. Of those, 1 critical and 5 high. 3 arrived with exploitation evidence or public exploit code already attached.

16
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 16 published.

CVE-2026-24061Critical· 9.8CISA KEVPoC
8mo ago

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

▾ Hadalgnu · inetutilsEPSS 99%via NVD
CVE-2026-22807High· 8.8PoC
8mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without gating on `trust_remote_…

▾ Midnightvllm · vllmEPSS 0.83%via NVD
CVE-2026-22822High· 8.8
8mo ago

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.20.2 and prior to version 1.2.0, the `getSecretKey` template function, while introd…

▾ Twilightexternal-secrets · external_secrets_operatorEPSS 0.19%via NVD
CVE-2025-13878High· 7.5
8mo ago

Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through …

Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through …

▾ TwilightEPSS 9.2%via NVD
CVE-2025-13465Medium· 5.3PoC
8mo ago

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion …

▾ Twilightlodash · lodashEPSS 1.8%via NVD
CVE-2026-24046High· 7.1
8mo ago

Backstage is an open framework for building developer portals

Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder…

▾ TwilightEPSS 0.53%via NVD
CVE-2026-23986High· 7.1
8mo ago

Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true

Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true

▾ Twilightcopier · copierEPSS 0.26%via OSV
CVE-2026-23946Medium· 6.8
8mo ago

Tendenci Affected by Authenticated Remote Code Execution via Pickle Deserialization

Tendenci Affected by Authenticated Remote Code Execution via Pickle Deserialization

▾ Sunlittendenci · tendenciEPSS 0.85%via OSV
CVE-2026-23968Medium· 5.5
8mo ago

Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false

Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false

▾ Sunlitcopier · copierEPSS 0.24%via OSV
CVE-2026-23960Medium· 5.4
8mo ago

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.6.17 and 3.7.8, stored XSS in the artifact directory listing allows any workflow author to execute arbit…

▾ Sunlitargoproj · argo_workflowsEPSS 0.40%via NVD
CVE-2026-23990Medium· 5.3
8mo ago

Flux Operator Web UI Impersonation Bypass via Empty OIDC Claims

Flux Operator Web UI Impersonation Bypass via Empty OIDC Claims

▾ Sunlitcontrolplaneio-fluxcd · github.com/controlplaneio-fluxcd/flux-operatorEPSS 0.35%via OSV
CVE-2026-23849Medium· 5.3
8mo ago

File Browser Vulnerable to Username Enumeration via Timing Attack in /api/login

File Browser Vulnerable to Username Enumeration via Timing Attack in /api/login

▾ Sunlitfilebrowser · github.com/filebrowser/filebrowserEPSS 0.49%via OSV

Most-affected vendors

By CVEs published in the period.