VulnSea

Daily digest

Tuesday 3 February 2026

A heavy day: 15 new CVEs, well above the recent average of about 9. Of those, 1 critical and 5 high. 3 arrived with exploitation evidence or public exploit code already attached. django was the most-affected vendor with 3.

15
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 15 published.

CVE-2025-64712Critical· 9.8
7mo ago

Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write

Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write

▾ Midnightunstructured · unstructuredEPSS 0.64%via OSV
CVE-2025-70560High· 8.4
7mo ago

Boltz contains an insecure deserialization vulnerability in its molecule loading functionality

Boltz contains an insecure deserialization vulnerability in its molecule loading functionality

▾ Twilightboltz · boltzEPSS 0.15%via OSV
CVE-2020-37094High· 8.1
7mo ago

EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to bypass two-factor authentication by exploiting token-to-password-hash mapping in application/Espo/Core/Utils/Authent…

EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to bypass two-factor authentication by exploiting token-to-password-hash mapping in application/Espo/Core/Utils/Authent…

▾ Twilightespocrm · espocrmEPSS 0.48%via NVD
CVE-2026-1207Medium· 5.4PoC
7mo ago

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupport…

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupport…

▾ Twilightdjangoproject · djangoEPSS 13%via NVD
CVE-2025-62673High· 8.0
7mo ago

Heap-based Buffer Overflow vulnerability in Archer AX53 v1.0 and AX12 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containin…

Heap-based Buffer Overflow vulnerability in Archer AX53 v1.0 and AX12 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containin…

▾ Twilighttp-link · archer_ax53_firmwareEPSS 0.55%via NVD
CVE-2026-1312Medium· 5.4PoC
7mo ago

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, w…

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, w…

▾ Twilightdjangoproject · djangoEPSS 0.85%via NVD
CVE-2025-69848Medium· 5.4PoC
7mo ago

NetBox is an open-source infrastructure resource modeling and IP address management platform

NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through 3.7.x in the ProtectedError handling logic, where object…

▾ Twilightnetbox · netboxEPSS 0.31%via NVD
CVE-2026-25223High· 7.5
7mo ago

Fastify is a fast and low overhead web framework, for Node.js

Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.2, a validation bypass vulnerability exists in Fastify where request body validation schemas specified by Content-Type can be completely circumvented. By…

▾ Twilightfastify · fastifyEPSS 0.82%via NVD
CVE-2026-25121High· 7.5
7mo ago

apko has a path traversal in apko dirFS which allows filesystem writes outside base

apko has a path traversal in apko dirFS which allows filesystem writes outside base

▾ Twilightapko · chainguard.dev/apkoEPSS 0.39%via OSV
CVE-2026-25122Medium· 5.5
7mo ago

apko affected by unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams

apko affected by unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams

▾ Sunlitapko · chainguard.dev/apkoEPSS 0.11%via OSV
CVE-2026-1287Medium· 5.4
7mo ago

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column aliases via control characters, using a suitably crafted dictionary, with dictionary expansio…

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column aliases via control characters, using a suitably crafted dictionary, with dictionary expansio…

▾ Sunlitdjangoproject · djangoEPSS 0.80%via NVD
CVE-2026-25517Medium
7mo ago

Wagtail has improper permission handling on admin preview endpoints

Wagtail has improper permission handling on admin preview endpoints

▾ Sunlitwagtail · wagtailEPSS 0.45%via OSV

Most-affected vendors

By CVEs published in the period.