VulnSea

Daily digest

Tuesday 24 February 2026

A heavy day: 13 new CVEs, well above the recent average of about 8. Of those, 1 critical and 5 high. 2 arrived with exploitation evidence or public exploit code already attached. apache-superset was the most-affected vendor with 5.

13
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 13 published.

CVE-2026-27483High· 8.8PoC
7mo ago

MindsDB: Path Traversal in /api/files Leading to Remote Code Execution

MindsDB: Path Traversal in /api/files Leading to Remote Code Execution

▾ Midnightmindsdb · mindsdbEPSS 8.8%via OSV
CVE-2026-2771Critical· 9.8
7mo ago

Undefined behavior in the DOM: Core & HTML component

Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

▾ Midnightmozilla · firefoxEPSS 0.61%via NVD
CVE-2024-56373High· 8.4
7mo ago

Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table

Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table

▾ Twilightapache-airflow · apache-airflowEPSS 1.1%via OSV
CVE-2026-25968High· 7.4
7mo ago

ImageMagick is free and open-source software used for editing and manipulating digital images

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a stack buffer overflow occurs when processing the an attribute in msl.c. A long value overflows a f…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-23984High
7mo ago

Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections

Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections

▾ Twilightapache-superset · apache-supersetEPSS 0.36%via OSV
CVE-2026-23982High
7mo ago

Apache Superset Improper Authorization allows low-privileged users to bypass access controls

Apache Superset Improper Authorization allows low-privileged users to bypass access controls

▾ Twilightapache-superset · apache-supersetEPSS 0.45%via OSV
CVE-2026-23980MediumPoC
7mo ago

Apache Superset allows privileged users to conduct error-based SQL Injection

Apache Superset allows privileged users to conduct error-based SQL Injection

▾ Twilightapache-superset · apache-supersetEPSS 0.65%via OSV
CVE-2025-27555Medium· 6.5
7mo ago

Apache Airflow exposes sensitive information in its log files

Apache Airflow exposes sensitive information in its log files

▾ Sunlitapache-airflow · apache-airflowEPSS 0.37%via OSV
CVE-2026-27469Medium· 6.1
7mo ago

Isso affected by Stored XSS via comment website field

Isso affected by Stored XSS via comment website field

▾ Sunlitisso · issoEPSS 0.37%via OSV
CVE-2026-27156Medium· 6.1
7mo ago

NiceGUI vulnerable to XSS via Code Injection during client-side element function execution

NiceGUI vulnerable to XSS via Code Injection during client-side element function execution

▾ Sunlitnicegui · niceguiEPSS 0.27%via OSV
CVE-2026-25969Medium· 5.3
7mo ago

ImageMagick is free and open-source software used for editing and manipulating digital images

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a memory leak exists in `coders/ashlar.c`. The `WriteASHLARImage` allocates a structure. However, when an exceptio…

▾ SunlitEPSS 0.48%via NVD
CVE-2026-23969Medium
7mo ago

Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine

Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine

▾ Sunlitapache-superset · apache-supersetEPSS 0.62%via OSV

Most-affected vendors

By CVEs published in the period.