VulnSea

Daily digest

Monday 2 February 2026

A heavy day: 22 new CVEs, well above the recent average of about 7. Severity skewed high: 2 critical and 12 high, 64% of the total. One arrived with exploitation evidence or public exploit code already attached. tp-link was the most-affected vendor with 3.

22
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 22 published.

CVE-2026-22778Critical· 9.8PoC
8mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a hea…

▾ Abyssalvllm · vllmEPSS 10%via NVD
CVE-2026-25481Critical
8mo ago

Langroid has WAF Bypass Leading to RCE in TableChatAgent

Langroid has WAF Bypass Leading to RCE in TableChatAgent

▾ Midnightlangroid · langroidEPSS 0.73%via OSV
CVE-2026-1761High· 8.6
8mo ago

A flaw was found in libsoup

A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted m…

▾ TwilightEPSS 1.0%via NVD
CVE-2026-0599High· 7.5
8mo ago

Hugging Face Text Generation Inference vulnerable to Uncontrolled Resource Consumption

Hugging Face Text Generation Inference vulnerable to Uncontrolled Resource Consumption

▾ Twilighttext-generation · text-generationEPSS 28%via OSV
CVE-2026-24737High· 8.1
8mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass u…

▾ Twilightparall · jspdfEPSS 0.55%via NVD
CVE-2026-1531High· 8.1
8mo ago

A flaw was found in foreman_kubevirt

A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set. This insecure default allows a remote attacker, c…

▾ TwilightEPSS 0.29%via NVD
CVE-2026-1530High· 8.1
8mo ago

A flaw was found in fog-kubevirt

A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) attack due to disabled certificate validation. This enables the attacker to intercept and potentially alter sensitive com…

▾ TwilightEPSS 0.26%via NVD
CVE-2026-1117High· 8.2
8mo ago

Lollms has an Improper Access Control vulnerability

Lollms has an Improper Access Control vulnerability

▾ Twilightlollms · lollmsEPSS 0.56%via OSV
CVE-2026-22223High· 8.0
8mo ago

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and BE3600 v1 (vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrati…

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and BE3600 v1 (vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrati…

▾ Twilighttp-link · archer_be230_firmwareEPSS 1.3%via NVD
CVE-2026-22221High· 8.0
8mo ago

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrativ…

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrativ…

▾ Twilighttp-link · archer_be230_firmwareEPSS 1.4%via NVD
CVE-2026-0631High· 8.0
8mo ago

An OS Command Injection vulnerability in OpenVPN modules in TP-Link Archer BE230 v1.2, BE3600v1 and AXE75 v1 allows an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain…

An OS Command Injection vulnerability in OpenVPN modules in TP-Link Archer BE230 v1.2, BE3600v1 and AXE75 v1 allows an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain…

▾ Twilighttp-link · archer_be230_firmwareEPSS 1.5%via NVD
CVE-2026-53874High
8mo ago

picklescan missing detection by simple obfuscation of a `builtins.eval` call

picklescan missing detection by simple obfuscation of a `builtins.eval` call

▾ Twilightpicklescan · picklescanEPSS 0.76%via OSV

Most-affected vendors

By CVEs published in the period.