Daily digest
Tuesday 27 January 2026
13 new CVEs this day, in line with the recent average. Severity skewed high: 1 critical and 10 high, 85% of the total. 4 arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 12 that matter most of the 13 published.
CVE-2025-15467High· 8.8PoCIssue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, …
Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, …
CVE-2026-24486High· 8.6PoCPython-Multipart is a streaming multipart parser for Python
Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write …
CVE-2026-21721High· 8.1PoCThe dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action
The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on ot…
CVE-2020-36939High· 7.5PoCCassandra Web - Remote File Read
Cassandra Web - Remote File Read
CVE-2026-24874Critical· 9.1Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before 2025.12.30.
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before 2025.12.30.
CVE-2026-24747High· 8.8PyTorch is a Python package that provides tensor computation
PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.l…
CVE-2026-24869High· 8.8Use-after-free in the Layout: Scrolling and Overflow component
Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability was fixed in Firefox 147.0.2.
CVE-2026-24882High· 8.4In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.
In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.
CVE-2026-24881High· 8.1In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling
In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily be leveraged for deni…
CVE-2026-21720High· 7.5Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image
Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that gorou…
CVE-2026-24779High· 7.1vLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side Request Forgery (SSRF) vulnerability exists in the `MediaConnector` class within the vLLM project's multimodal feature set. …
CVE-2026-23892Medium· 5.9OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication
OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication
Most-affected vendors
By CVEs published in the period.