VulnSea

Daily digest

Wednesday 25 February 2026

A heavy day: 22 new CVEs, well above the recent average of about 10. Of those, 3 critical and 6 high. 6 arrived with exploitation evidence or public exploit code already attached. rucio-webui was the most-affected vendor with 6.

22
New CVEs
3
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 22 published.

CVE-2026-27577Critical· 9.9PoC
7mo ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and patched following CVE-2025-68613. An authenticated user w…

▾ Abyssaln8n · n8nEPSS 1.0%via NVD
CVE-2026-27727Critical· 9.8PoC
7mo ago

mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked…

mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked…

▾ Abyssalmchange · mchange_commons_javaEPSS 1.6%via NVD
CVE-2026-27606Critical· 9.8PoC
7mo ago

Rollup is a module bundler for JavaScript

Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure …

▾ Abyssalrollupjs · rollupEPSS 1.5%via NVD
CVE-2026-27696High· 8.6
7mo ago

changedetection.io is Vulnerable to SSRF via Watch URLs

changedetection.io is Vulnerable to SSRF via Watch URLs

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.48%via OSV
CVE-2026-27645Medium· 6.1PoC
7mo ago

changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response

changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.49%via OSV
CVE-2026-27608High· 8.1
7mo ago

Parse Dashboard is a standalone dashboard for managing Parse Server apps

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /apps/:appId/agent`) does not enforce authorization. Authenticated users scoped …

▾ TwilightEPSS 0.38%via NVD
CVE-2026-25136High· 8.1
7mo ago

Rucio WebUI has a Reflected Cross-site Scripting Vulnerability

Rucio WebUI has a Reflected Cross-site Scripting Vulnerability

▾ Twilightrucio-webui · rucio-webuiEPSS 0.27%via OSV
CVE-2026-26986Medium· 5.5PoC
7mo ago

FreeRDP has heap-use-after-free in rail_window_free

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `rail_window_free` dereferences a freed `xfAppWindow` pointer during `HashTable_Free` cleanup because `xf_rail_window_common` calls `free(appWindow…

▾ TwilightFreeRDP · FreeRDPEPSS 0.79%via CVEORG
CVE-2026-27628High· 7.5
7mo ago

pypdf: possible infinite loop when loading circular /Prev entries in cross-reference streams (CVE-2026-27628)

A flaw was found in pypdf. Processing a specially crafted PDF document, specifically with circular /Prev references in the cross-reference (xref) chain, can cause an infinite loop and a high consumption of CPU, resulting in a denial of ser…

▾ TwilightRed Hat · Red Hat Quay 3.16EPSS 0.61%via CSAF
CVE-2026-27595High· 7.5
7mo ago

Parse Dashboard is a standalone dashboard for managing Parse Server apps

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (POST `/apps/:appId/agent`) has multiple security vulnerabilities that, when chained, a…

▾ TwilightEPSS 0.64%via NVD
CVE-2026-25733High· 7.3
7mo ago

Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function

Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function

▾ Twilightrucio-webui · rucio-webuiEPSS 0.41%via OSV
CVE-2026-26717Medium· 4.8PoC
7mo ago

OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function

OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function

▾ Twilightrichie · richieEPSS 0.51%via OSV

Most-affected vendors

By CVEs published in the period.