Daily digest
Thursday 5 February 2026
8 new CVEs this day, in line with the recent average. Of those, 2 high. CISA added one CVE to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this day, ranked by depth score
The 8 that matter most of the 8 published.
CVE-2025-61732High· 8.6A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
CVE-2026-1707High· 7.4pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerability
pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerability
CVE-2025-12131Medium· 6.5A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.
A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.
CVE-2026-25516Medium· 6.1NiceGUI's XSS vulnerability in ui.markdown() allows arbitrary JavaScript execution through unsanitized HTML content
NiceGUI's XSS vulnerability in ui.markdown() allows arbitrary JavaScript execution through unsanitized HTML content
CVE-2020-37131Medium· 6.2Nsauditor Product Key Explorer 4.2.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by inputting a specially crafted registration key
Nsauditor Product Key Explorer 4.2.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by inputting a specially crafted registration key. Attackers can generate a payload of 1000 bytes of r…
CVE-2020-37121Medium· 5.5CODE::BLOCKS 16.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler with crafted Unicode characters
CODE::BLOCKS 16.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler with crafted Unicode characters. Attackers can create a malicious text file with 1982…
CVE-2026-25198Medium· 4.7web2py has an Open Redirect Vulnerability
web2py has an Open Redirect Vulnerability
CVE-2025-68121NoneUnexpected session resumption in crypto/tls
Unexpected session resumption in crypto/tls
Most-affected vendors
By CVEs published in the period.