VulnSea

Daily digest

Monday 26 January 2026

A busier-than-usual day with 13 new CVEs (recent average about 11). Of those, 5 high. 2 arrived with exploitation evidence or public exploit code already attached. CISA added 3 CVEs to the Known Exploited Vulnerabilities catalog.

13
New CVEs
0
Critical
3
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 13 published.

CVE-2026-21509High· 7.8CISA KEV0dayPoC
8mo ago

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

▾ Abyssalmicrosoft · 365_appsEPSS 71%via NVD
CVE-2025-14459High· 8.5
8mo ago

A flaw was found in KubeVirt Containerized Data Importer (CDI)

A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolumeClaims (PVCs) from unauthorized namespaces, resulting in unauthorized access to data via the DataImportCron PVC sou…

▾ TwilightEPSS 0.38%via NVD
CVE-2026-24490High· 8.1
8mo ago

MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field

MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field

▾ Twilightmobsf · mobsfEPSS 0.35%via OSV
CVE-2026-23864High· 7.5
8mo ago

Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending s…

Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending s…

▾ Twilightfacebook · reactEPSS 2.6%via NVD
CVE-2026-24123High· 7.4
8mo ago

BentoML has a Path Traversal via Bentofile Configuration

BentoML has a Path Traversal via Bentofile Configuration

▾ Twilightbentoml · bentomlEPSS 0.50%via OSV
CVE-2026-24688MediumPoC
8mo ago

pypdf has possible Infinite Loop when processing outlines/bookmarks

pypdf has possible Infinite Loop when processing outlines/bookmarks

▾ Twilightpypdf · pypdfEPSS 0.45%via OSV
CVE-2025-14525Medium· 6.4
8mo ago

A flaw was found in kubevirt

A flaw was found in kubevirt. A user within a virtual machine (VM), if the guest agent is active, can exploit this by causing the agent to report an excessive number of network interfaces. This action can overwhelm the system's ability t…

▾ SunlitRed Hat · kubevirtEPSS 0.29%via NVD
CVE-2025-11687Medium· 6.1
8mo ago

GI-DocGen vulnerable to Reflected XSS via unescaped query strings

GI-DocGen vulnerable to Reflected XSS via unescaped query strings

▾ Sunlitgi-docgen · gi-docgenEPSS 0.38%via OSV
CVE-2026-24489Medium· 5.3
8mo ago

Gakido vulnerable to HTTP Header Injection (CRLF Injection)

Gakido vulnerable to HTTP Header Injection (CRLF Injection)

▾ Sunlitgakido · gakidoEPSS 0.40%via OSV
CVE-2025-11065Medium· 5.3
8mo ago

A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode

A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive input valu…

▾ Sunlitgo-viper · github.com/go-viper/mapstructure/v2EPSS 0.41%via NVD
CVE-2025-9820Medium· 4.0
8mo ago

A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization

A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-…

▾ SunlitEPSS 0.23%via NVD
CVE-2025-9615Low· 3.3
8mo ago

A flaw was found in NetworkManager

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can ac…

▾ SunlitEPSS 0.16%via NVD

Most-affected vendors

By CVEs published in the period.