VulnSea

Daily digest

Friday 6 February 2026

9 new CVEs this day, in line with the recent average. Severity skewed high: 2 critical and 4 high, 67% of the total. 2 arrived with exploitation evidence or public exploit code already attached.

9
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 9 that matter most of the 9 published.

CVE-2026-1709Critical· 9.4
7mo ago

A flaw was found in Keylime

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network ac…

▾ Midnightkeylime · keylimeEPSS 5.5%via NVD
GHSA-4f84-67cv-qrv3Critical
7mo ago

A single post-release of dydx-v4-client contained obfuscated multi-stage loader

A single post-release of dydx-v4-client contained obfuscated multi-stage loader

▾ Midnightdydx-v4-client · dydx-v4-clientvia OSV
CVE-2026-25580High· 8.6
7mo ago

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) vulnerability exists in Pydantic AI's URL download functionality. When …

▾ Twilightpydantic · pydantic_aiEPSS 0.67%via NVD
CVE-2026-2015Medium· 6.3PoC
7mo ago

A weakness has been identified in Portabilis i-Educar up to 2.10

A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the component Final Status Import. Executing a manipulation of the argument school_id can lead …

▾ Twilightportabilis · i-educarEPSS 0.31%via NVD
CVE-2026-1337Medium· 5.4PoC
7mo ago

Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML

Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j prod…

▾ Twilightneo4j · neo4jEPSS 0.23%via NVD
CVE-2026-25793High
7mo ago

Blocklist Bypass possible via ECDSA Signature Malleability

Blocklist Bypass possible via ECDSA Signature Malleability

▾ Twilightslackhq · github.com/slackhq/nebulaEPSS 0.17%via OSV
CVE-2026-25650High
7mo ago

MCP-Salesforce's arbitrary attribute access leads to disclosure of Salesforce auth token

MCP-Salesforce's arbitrary attribute access leads to disclosure of Salesforce auth token

▾ Twilightmcp-salesforce-connector · mcp-salesforce-connectorEPSS 0.53%via OSV
CVE-2026-25640High· 7.1
7mo ago

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to before 1.51.0, a path traversal vulnerability in the Pydantic AI web UI allows an attacker to serve arbitrary JavaScript …

▾ Twilightpydantic · pydantic_aiEPSS 0.41%via NVD
CVE-2025-13818Medium· 6.7
7mo ago

Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent

Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent

▾ Sunliteset · management_agentEPSS 0.13%via NVD

Most-affected vendors

By CVEs published in the period.