VulnSea

Daily digest

Friday 30 January 2026

8 new CVEs this day, in line with the recent average. Severity skewed high: 5 high, 63% of the total. 2 arrived with exploitation evidence or public exploit code already attached.

8
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 8 that matter most of the 8 published.

CVE-2025-24293High· 8.1PoC
8mo ago

# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three me…

# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three me…

▾ MidnightEPSS 5.5%via NVD
CVE-2025-1395High· 8.2
8mo ago

Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technologies Inc

Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technologies Inc. HeyGarson allows Fuzzing for application mapping. This issue affects HeyGarson: through 30012026.  NOTE: Th…

▾ TwilightEPSS 0.33%via NVD
CVE-2025-62348High· 7.8
8mo ago

Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload

Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload

▾ Twilightsalt · saltEPSS 0.20%via OSV
CVE-2026-25153High· 7.7
8mo ago

Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs

Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11 and 1.14.1, when Tec…

▾ Twilightlinuxfoundation · backstageEPSS 0.61%via NVD
CVE-2024-4027High· 7.5
8mo ago

A flaw was found in Undertow

A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unaut…

▾ TwilightEPSS 0.39%via NVD
CVE-2025-62349Medium· 6.2
8mo ago

Salt Authentication Protocol Version Downgrade Allows Minion Impersonation

Salt Authentication Protocol Version Downgrade Allows Minion Impersonation

▾ Sunlitsalt · saltEPSS 0.46%via OSV
CVE-2026-25211Low· 3.2PoC
8mo ago

Llama Stack exposes secret in initialization log

Llama Stack exposes secret in initialization log

▾ Twilightllama-stack · llama-stackEPSS 0.24%via OSV
CVE-2026-1498None
8mo ago

An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web inter…

An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web inter…

▾ SunlitEPSS 0.92%via NVD

Most-affected vendors

By CVEs published in the period.