VulnSea

Daily digest

Monday 23 February 2026

6 new CVEs this day, in line with the recent average. Severity skewed high: 4 high, 67% of the total. 2 arrived with exploitation evidence or public exploit code already attached.

6
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 6 that matter most of the 6 published.

CVE-2026-26331High· 8.8PoC
7mo ago

yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option

yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option

▾ Midnightyt-dlp · yt-dlpEPSS 2.0%via OSV
CVE-2026-25747High· 8.8PoC
7mo ago

Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without a…

Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without a…

▾ Midnightapache · camelEPSS 0.89%via NVD
CVE-2026-2998High· 7.8
7mo ago

ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitrary code.

ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitrary code.

▾ TwilightEPSS 0.17%via NVD
CVE-2025-14905High· 7.2
7mo ago

A flaw was found in the 389-ds-base server

A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summin…

▾ TwilightEPSS 1.2%via NVD
CVE-2026-2970Medium· 4.6
7mo ago

datapizza-ai has unsafe deserialization via pickle.loads() in RedisCache

datapizza-ai has unsafe deserialization via pickle.loads() in RedisCache

▾ Sunlitdatapizza-ai-core · datapizza-ai-coreEPSS 1.1%via OSV
CVE-2026-2969Medium· 4.7
7mo ago

datapizza-ai: Server-Side Template Injection in ChatPromptTemplate via Jinja2 Template Handler

datapizza-ai: Server-Side Template Injection in ChatPromptTemplate via Jinja2 Template Handler

▾ Sunlitdatapizza-ai-core · datapizza-ai-coreEPSS 0.79%via OSV

Most-affected vendors

By CVEs published in the period.