VulnSea

Daily digest

Wednesday 4 February 2026

A heavy day: 21 new CVEs, well above the recent average of about 9. Of those, 5 high. One arrived with exploitation evidence or public exploit code already attached. Linux was the most-affected vendor with 11.

21
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 21 published.

CVE-2026-25521High· 8.8
7mo ago

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype pollution vulnerability exists in locutus. Despite a previous fix that attempted to mitig…

▾ Twilightlocutus · locutusEPSS 0.44%via NVD
CVE-2026-24514Medium· 6.5PoC
7mo ago

ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling

ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling

▾ Twilightingress-nginx · k8s.io/ingress-nginxEPSS 0.49%via OSV
CVE-2026-23074High· 7.8
7mo ago

In the Linux kernel, the following vulnerability has been resolved: net/sched: Enforce that teql can only be used as root qdisc Design intent of teql is that it is only supposed to be used as root qdisc. We need to check for that const…

In the Linux kernel, the following vulnerability has been resolved: net/sched: Enforce that teql can only be used as root qdisc Design intent of teql is that it is only supposed to be used as root qdisc. We need to check for that const…

▾ Twilightlinux · linux_kernelEPSS 0.14%via NVD
CVE-2026-23095High· 7.5
7mo ago

gue: Fix skb memleak with inner IP protocol 0.

In the Linux kernel, the following vulnerability has been resolved: gue: Fix skb memleak with inner IP protocol 0. syzbot reported skb memleak below. [0] The repro generated a GUE packet with its inner protocol 0. gue_udp_recv() retu…

▾ TwilightLinux · LinuxEPSS 0.25%via CVEORG
CVE-2026-20119High· 7.5
7mo ago

Cisco TelePresence Collaboration Endpoint Software and RoomOS Software Denial of Service Vulnerability (CVE-2026-20119)

A vulnerability in the text rendering subsystem of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affecte…

▾ TwilightCisco · Cisco RoomOS SoftwareEPSS 0.38%via CSAF
CVE-2026-25536High· 7.1
7mo ago

MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients

MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multi…

▾ Twilightlfprojects · mcp_typescript_sdkEPSS 0.36%via NVD
CVE-2026-25145Medium· 5.5
7mo ago

melange has a path traversal in license-path which allows reading files outside workspace

melange has a path traversal in license-path which allows reading files outside workspace

▾ Sunlitmelange · chainguard.dev/melangeEPSS 0.18%via OSV
CVE-2026-23103Medium· 4.7⚖ disputed
7mo ago

kernel: ipvlan: Make the addrs_lock be per port (CVE-2026-23103)

A race condition vulnerability was found in the Linux kernel's ipvlan driver. The per-device addrs_lock was incorrectly used instead of a per-port lock, and some code paths (ipvlan_open/ipvlan_close) failed to acquire the lock entirely. Fo…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.11%via CSAF
CVE-2026-20111Medium· 4.8
7mo ago

A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system.…

A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system.…

▾ Sunlitcisco · prime_infrastructureEPSS 0.19%via NVD
CVE-2026-20123Medium· 4.3
7mo ago

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This…

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This…

▾ Sunlitcisco · evolved_programmable_network_managerEPSS 0.19%via NVD
CVE-2026-24513Low· 3.1
7mo ago

ingress-nginx has Improper Check for Unusual or Exceptional Conditions

ingress-nginx has Improper Check for Unusual or Exceptional Conditions

▾ Sunlitingress-nginx · k8s.io/ingress-nginxEPSS 0.32%via OSV
CVE-2026-23110None
7mo ago

scsi: core: Wake up the error handler when final completions race against each other

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Wake up the error handler when final completions race against each other The fragile ordering between marking commands completed or failed so that the erro…

▾ SunlitLinux · LinuxEPSS 0.10%via CVEORG

Most-affected vendors

By CVEs published in the period.