Daily digest
Friday 30 January 2026
8 new CVEs this day, in line with the recent average. Severity skewed high: 5 high, 63% of the total. 2 arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 8 that matter most of the 8 published.
CVE-2025-24293High· 8.1PoC# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three me…
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three me…
CVE-2025-1395High· 8.2Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technologies Inc
Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technologies Inc. HeyGarson allows Fuzzing for application mapping. This issue affects HeyGarson: through 30012026. NOTE: Th…
CVE-2025-62348High· 7.8Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload
Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload
CVE-2026-25153High· 7.7Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs
Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11 and 1.14.1, when Tec…
CVE-2024-4027High· 7.5A flaw was found in Undertow
A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unaut…
CVE-2025-62349Medium· 6.2Salt Authentication Protocol Version Downgrade Allows Minion Impersonation
Salt Authentication Protocol Version Downgrade Allows Minion Impersonation
CVE-2026-25211Low· 3.2PoCLlama Stack exposes secret in initialization log
Llama Stack exposes secret in initialization log
CVE-2026-1498NoneAn LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web inter…
An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web inter…
Most-affected vendors
By CVEs published in the period.