Daily digest
Tuesday 3 February 2026
A heavy day: 15 new CVEs, well above the recent average of about 9. Of those, 1 critical and 5 high. 3 arrived with exploitation evidence or public exploit code already attached. django was the most-affected vendor with 3.
New this day, ranked by depth score
The 12 that matter most of the 15 published.
CVE-2025-64712Critical· 9.8Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
CVE-2025-70560High· 8.4Boltz contains an insecure deserialization vulnerability in its molecule loading functionality
Boltz contains an insecure deserialization vulnerability in its molecule loading functionality
CVE-2020-37094High· 8.1EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to bypass two-factor authentication by exploiting token-to-password-hash mapping in application/Espo/Core/Utils/Authent…
EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to bypass two-factor authentication by exploiting token-to-password-hash mapping in application/Espo/Core/Utils/Authent…
CVE-2026-1207Medium· 5.4PoCAn issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupport…
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupport…
CVE-2025-62673High· 8.0Heap-based Buffer Overflow vulnerability in Archer AX53 v1.0 and AX12 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containin…
Heap-based Buffer Overflow vulnerability in Archer AX53 v1.0 and AX12 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containin…
CVE-2026-1312Medium· 5.4PoCAn issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, w…
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, w…
CVE-2025-69848Medium· 5.4PoCNetBox is an open-source infrastructure resource modeling and IP address management platform
NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through 3.7.x in the ProtectedError handling logic, where object…
CVE-2026-25223High· 7.5Fastify is a fast and low overhead web framework, for Node.js
Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.2, a validation bypass vulnerability exists in Fastify where request body validation schemas specified by Content-Type can be completely circumvented. By…
CVE-2026-25121High· 7.5apko has a path traversal in apko dirFS which allows filesystem writes outside base
apko has a path traversal in apko dirFS which allows filesystem writes outside base
CVE-2026-25122Medium· 5.5apko affected by unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams
apko affected by unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams
CVE-2026-1287Medium· 5.4An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column aliases via control characters, using a suitably crafted dictionary, with dictionary expansio…
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column aliases via control characters, using a suitably crafted dictionary, with dictionary expansio…
CVE-2026-25517MediumWagtail has improper permission handling on admin preview endpoints
Wagtail has improper permission handling on admin preview endpoints
Most-affected vendors
By CVEs published in the period.