VulnSea

Daily digest

Monday 4 May 2026

A heavy day: 34 new CVEs, well above the recent average of about 14. Severity skewed high: 6 critical and 16 high, 65% of the total. 2 arrived with exploitation evidence or public exploit code already attached. openc3 was the most-affected vendor with 4.

34
New CVEs
6
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 34 published.

CVE-2026-7482Critical· 9.1PoC
4mo ago

Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader

Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader

▾ Abyssalollama · github.com/ollama/ollamaEPSS 0.71%via OSV
CVE-2026-42601Critical· 9.8
4mo ago

ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView

ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView

▾ Midnightarchivebox · archiveboxEPSS 0.60%via OSV
CVE-2026-42027Critical· 9.8⚖ disputed
4mo ago

Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description:  The ExtensionLoader.instantiateExtension(Class, String) method loa…

Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description:  The ExtensionLoader.instantiateExtension(Class, String) method loa…

▾ Midnightapache · opennlpEPSS 1.3%via NVD
CVE-2026-24781Critical· 9.8
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to write code which can escape from the VM2 sandbox and execute …

▾ Midnightvm2_project · vm2EPSS 1.2%via NVD
CVE-2026-42154High· 7.5PoC
4mo ago

Prometheus is an open-source monitoring system and time series database

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before…

▾ Midnightprometheus · prometheusEPSS 0.89%via NVD
CVE-2026-42087Critical· 9.6
4mo ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.…

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSD…

▾ Midnightopenc3 · openc3EPSS 0.45%via OSV
CVE-2026-40682Critical· 9.1
4mo ago

XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a static SAXParserFa…

XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a static SAXParserFa…

▾ Midnightapache · opennlpEPSS 0.84%via NVD
CVE-2026-6266High· 8.3
4mo ago

A flaw was found in the AAP gateway

A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external Identity Provider (IDP) identity to an existing AAP user account based on email matching without verifying email own…

▾ TwilightEPSS 0.57%via NVD
CVE-2026-42088High· 8.1
4mo ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version …

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from th…

▾ Twilightopenc3 · openc3EPSS 0.49%via OSV
CVE-2026-42084High· 8.1
4mo ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions…

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their passwo…

▾ Twilightopenc3 · openc3EPSS 0.44%via OSV
CVE-2025-67796High· 8.1
4mo ago

IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users

IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users

▾ Twilightrdiffweb · rdiffwebEPSS 0.24%via OSV
CVE-2026-24082High· 7.8
4mo ago

Memory Corruption when copying data from a freed source while executing performance counter deselect operation.

Memory Corruption when copying data from a freed source while executing performance counter deselect operation.

▾ TwilightEPSS 0.07%via NVD

Most-affected vendors

By CVEs published in the period.