VulnSea

Daily digest

Friday 23 January 2026

A heavy day: 17 new CVEs, well above the recent average of about 11. Severity skewed high: 2 critical and 8 high, 59% of the total. 5 arrived with exploitation evidence or public exploit code already attached. Linux was the most-affected vendor with 6.

17
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 17 published.

CVE-2026-24423Critical· 9.8CISA KEVPoC
8mo ago

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the …

▾ Hadalsmartertools · smartermailEPSS 88%via NVD
CVE-2026-0770HighCISA KEV0dayPoC
8mo ago

Langflow affected by Remote Code Execution via validate_code() exec()

Langflow affected by Remote Code Execution via validate_code() exec()

▾ Abyssallangflow · langflowEPSS 64%via OSV
CVE-2025-15059High· 7.80day
8mo ago

GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vu…

▾ Abyssalgimp · gimpEPSS 0.85%via NVD
CVE-2026-0775High· 7.00day
8mo ago

npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability

npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of npm cli. An attacker must first obtain the ability to execute…

▾ AbyssalEPSS 0.30%via NVD
CVE-2026-0603High· 8.3PoC
8mo ago

A flaw was found in Hibernate

A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrCl…

▾ MidnightRed Hat · Red Hat JBoss EAP 7.4 ELS for RHEL 8EPSS 0.87%via NVD
CVE-2026-0994High· 7.5PoC
8mo ago

A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth ac…

A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth ac…

▾ Midnightgoogle · protobufEPSS 0.72%via NVD
CVE-2025-66719Critical· 9.1
8mo ago

Free5gc NRF is vulnerable to scope validation bypass via maliciously crafted targetNF value

Free5gc NRF is vulnerable to scope validation bypass via maliciously crafted targetNF value

▾ Midnightfree5gc · github.com/free5gc/nrfEPSS 0.35%via OSV
CVE-2026-22980High· 7.8
8mo ago

nfsd: provide locking for v4_end_grace

In the Linux kernel, the following vulnerability has been resolved: nfsd: provide locking for v4_end_grace Writing to v4_end_grace can race with server shutdown and result in memory being accessed after it was freed - reclaim_str_hasht…

▾ TwilightLinux · LinuxEPSS 0.15%via CVEORG
CVE-2026-22992High· 7.5
8mo ago

libceph: return the handler error from mon_handle_auth_done()

In the Linux kernel, the following vulnerability has been resolved: libceph: return the handler error from mon_handle_auth_done() Currently any error from ceph_auth_handle_reply_done() is propagated via finish_auth() but isn't returned…

▾ TwilightLinux · LinuxEPSS 0.32%via CVEORG
CVE-2025-71161High· 7.5
8mo ago

dm-verity: disable recursive forward error correction

In the Linux kernel, the following vulnerability has been resolved: dm-verity: disable recursive forward error correction There are two problems with the recursive correction: 1. It may cause denial-of-service. In fec_read_bufs, there…

▾ TwilightLinux · LinuxEPSS 0.38%via CVEORG
CVE-2025-52023Medium· 5.3
8mo ago

A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed error messages that disclose internal file paths, code snippets, and stack traces

A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed error messages that disclose internal file paths, code snippets, and stack traces. This occurs when s…

▾ Sunlitaptsys · gemscms_backendEPSS 0.45%via NVD
CVE-2026-0766NonePoC
8mo ago

Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design,…

Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design,…

▾ TwilightEPSS 26%via NVD

Most-affected vendors

By CVEs published in the period.