VulnSea

Daily digest

Friday 20 February 2026

7 new CVEs this day, in line with the recent average. Severity skewed high: 1 critical and 4 high, 71% of the total. 2 arrived with exploitation evidence or public exploit code already attached.

7
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 7 that matter most of the 7 published.

CVE-2026-2635High· 7.30day⚖ disputed
7mo ago

MLflow Use of Default Password Authentication Bypass Vulnerability

MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. T…

▾ AbyssalMLflow · MLflowEPSS 1.2%via NVD
CVE-2026-25896Critical· 9.3PoC⚖ disputed
7mo ago

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard…

▾ Abyssalnaturalintelligence · fast-xml-parserEPSS 0.50%via NVD
CVE-2026-2472HighPoC
7mo ago

Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)

Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)

▾ Midnightgoogle-cloud-aiplatform · google-cloud-aiplatformEPSS 0.54%via OSV
CVE-2026-2473High
7mo ago

Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming

Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming

▾ Twilightgoogle-cloud-aiplatform · google-cloud-aiplatformEPSS 0.46%via OSV
CVE-2019-25434High· 7.5
7mo ago

SpotAuditor 5.3.1.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting excessive data in the registration name field

SpotAuditor 5.3.1.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting excessive data in the registration name field. Attackers can enter a large string of characters (…

▾ Twilightnsasoft · spotauditorEPSS 0.32%via NVD
CVE-2026-27482Medium· 5.9
7mo ago

Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)

Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)

▾ Sunlitray · rayEPSS 0.40%via OSV
CVE-2026-21620None
7mo ago

Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative Path Traversal

Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative Path Traversal. Thi…

▾ SunlitEPSS 0.48%via NVD

Most-affected vendors

By CVEs published in the period.