VulnSea

Daily digest

Friday 27 February 2026

A quiet day: only 5 new CVEs against a recent average of about 11. Severity skewed high: 2 critical and 1 high, 60% of the total.

5
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 5 that matter most of the 5 published.

CVE-2026-21660Critical· 9.8
7mo ago

A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, an…

A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, an…

▾ Midnightjohnsoncontrols · frick_controls_quantum_hd_firmwareEPSS 0.23%via NVD
CVE-2026-28231Critical· 9.1
7mo ago

pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the en…

pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path buffer validation of `_pillow_heif.c` allows an attacker to bypass bounds checks by provid…

▾ Midnightpi-heif · pi-heifEPSS 0.71%via OSV
CVE-2025-10990High· 7.5
7mo ago

A flaw was found in REXML

A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processing hex numeric character references (&#x...;) in XML documents. This could lead to a Regular Expression Denial of Serv…

▾ TwilightEPSS 0.49%via NVD
GHSA-747p-wmpv-9c78Medium· 5.9
7mo ago

AWS CLI: cli_history database does not restrict file permissions on Unix systems

AWS CLI: cli_history database does not restrict file permissions on Unix systems

▾ Sunlitawscli · awsclivia OSV
CVE-2025-12150Low· 3.1
7mo ago

A flaw was found in Keycloak’s WebAuthn registration component

A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object wit…

▾ Sunlitredhat · build_of_keycloakEPSS 0.21%via NVD

Most-affected vendors

By CVEs published in the period.