VulnSea

Daily digest

Wednesday 6 May 2026

A heavy day: 57 new CVEs, well above the recent average of about 22. Severity skewed high: 7 critical and 23 high, 53% of the total. 2 arrived with exploitation evidence or public exploit code already attached. linux was the most-affected vendor with 12.

57
New CVEs
7
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 57 published.

CVE-2026-44335Critical· 9.8
4mo ago

PraisonAI has an SSRF bypass

PraisonAI has an SSRF bypass

▾ Midnightpraisonaiagents · praisonaiagentsEPSS 0.57%via OSV
CVE-2026-43198Critical· 9.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late. After tcp_v4_syn_recv_sock…

In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late. After tcp_v4_syn_recv_sock…

▾ Midnightlinux · linux_kernelEPSS 0.40%via NVD
CVE-2026-43125Critical· 9.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The len parameter in dlm_dump_rsb_name() is not validated and comes from network messages

In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The len parameter in dlm_dump_rsb_name() is not validated and comes from network messages. When it exceeds DLM_RESNAME_MAXL…

▾ Midnightlinux · linux_kernelEPSS 0.43%via NVD
CVE-2026-23870High· 7.5PoC
4mo ago

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following pac…

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following pac…

▾ Midnightfacebook · react-server-dom-parcelEPSS 1.5%via NVD
CVE-2026-44112Critical· 9.6
4mo ago

OpenClaw < 2026.4.22 - Symlink Swap Race Condition in OpenShell FS Bridge Writes

OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside the intended mount root. Attackers can exploit symlink swaps during fil…

▾ MidnightOpenClaw · OpenClawEPSS 0.39%via CVEORG
CVE-2026-42557Critical· 9.6
4mo ago

JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content

JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content

▾ Midnightjupyterlab · jupyterlabEPSS 0.71%via OSV
CVE-2026-43114Critical· 9.4
4mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry New test case fails unexpectedly when avx2 matching functions are used. The test first loads…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry New test case fails unexpectedly when avx2 matching functions are used. The test first loads…

▾ Midnightlinux · linux_kernelEPSS 0.67%via NVD
CVE-2026-43197Critical· 9.1
4mo ago

In the Linux kernel, the following vulnerability has been resolved: netconsole: avoid OOB reads, msg is not nul-terminated msg passed to netconsole from the console subsystem is not guaranteed to be nul-terminated

In the Linux kernel, the following vulnerability has been resolved: netconsole: avoid OOB reads, msg is not nul-terminated msg passed to netconsole from the console subsystem is not guaranteed to be nul-terminated. Before recent commit…

▾ Midnightlinux · linux_kernelEPSS 0.65%via NVD
CVE-2026-44115High· 8.8
4mo ago

OpenClaw < 2026.4.22 - Shell Expansion Bypass in Unquoted Heredocs via Exec Allowlist

OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can bypass allowlist validation by embedding shell expansion tokens in heredoc bodies to ex…

▾ TwilightOpenClaw · OpenClawEPSS 0.61%via CVEORG
CVE-2026-43112High· 8.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath When cifs_sanitize_prepath is called with an empty string or a string containing only delimiters (e.g., …

In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath When cifs_sanitize_prepath is called with an empty string or a string containing only delimiters (e.g., …

▾ Twilightlinux · linux_kernelEPSS 0.68%via NVD
CVE-2026-20034High· 8.8
4mo ago

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient validation of use…

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient validation of use…

▾ Twilightcisco · unity_connectionEPSS 0.71%via NVD
CVE-2026-42503High· 8.8
4mo ago

gopls by default communicates via pipe

gopls by default communicates via pipe. However, -port and -listen flags are supported as means of debugging. If -listen is given a value without an explicit host (e.g. :8080), or -port is used, gopls will listen on 0.0.0.0.  As a result…

▾ Twilightgolang · goplsEPSS 0.35%via NVD

Most-affected vendors

By CVEs published in the period.