VulnSea

Daily digest

Thursday 12 February 2026

A quiet day: only 9 new CVEs against a recent average of about 18. Severity skewed high: 5 high, 56% of the total. One arrived with exploitation evidence or public exploit code already attached. postgresql was the most-affected vendor with 4.

9
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 9 that matter most of the 9 published.

CVE-2026-2005High· 8.8PoC
7mo ago

Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database

Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

▾ Midnightpostgresql · postgresqlEPSS 1.3%via NVD
CVE-2026-2006High· 8.8
7mo ago

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running…

▾ Twilightpostgresql · postgresqlEPSS 1.1%via NVD
CVE-2026-2004High· 8.8
7mo ago

Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database

Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 1…

▾ Twilightpostgresql · postgresqlEPSS 1.2%via NVD
CVE-2026-2007High· 8.2
7mo ago

Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string

Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of a…

▾ Twilightpostgresql · postgresqlEPSS 0.50%via NVD
CVE-2026-25949High· 7.5
7mo ago

Traefik is an HTTP reverse proxy and load balancer

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unauthenticated client can bypass Traefik entrypoint respondingTimeouts.readTimeout by sendi…

▾ Twilighttraefik · traefikEPSS 0.82%via NVD
CVE-2026-21438Medium· 5.3
7mo ago

webtransport-go: Memory Exhaustion Attack due to Missing Cleanup of Streams Map

webtransport-go: Memory Exhaustion Attack due to Missing Cleanup of Streams Map

▾ Sunlitquic-go · github.com/quic-go/webtransport-goEPSS 0.38%via OSV
CVE-2026-63762Medium
7mo ago

SurrealDB vulnerable to Denial of Service through scripting function memory edge case

SurrealDB vulnerable to Denial of Service through scripting function memory edge case

▾ Sunlitsurrealdb · surrealdbEPSS 0.45%via OSV
CVE-2025-69752Medium· 4.3
7mo ago

An issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view other users' profile information by modifying the objectKey HTTP parameter in the My Details page URL.

An issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view other users' profile information by modifying the objectKey HTTP parameter in the My Details page URL.

▾ SunlitEPSS 0.17%via NVD
CVE-2025-67860Low· 3.8
7mo ago

NeuVector scanner insecurely handles passwords as command arguments

NeuVector scanner insecurely handles passwords as command arguments

▾ Sunlitneuvector · github.com/neuvector/scannerEPSS 0.09%via OSV

Most-affected vendors

By CVEs published in the period.