VulnSea

Daily digest

Wednesday 13 May 2026

A heavy day: 84 new CVEs, well above the recent average of about 52. Severity skewed high: 9 critical and 47 high, 67% of the total. 13 arrived with exploitation evidence or public exploit code already attached. vm2_project was the most-affected vendor with 11.

84
New CVEs
9
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 84 published.

CVE-2026-44578High· 8.6PoC
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted…

▾ Midnightvercel · next.jsEPSS 1.9%via NVD
CVE-2026-42945High· 8.1PoC
4mo ago

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expre…

▾ Midnightf5 · dosEPSS 3.4%via NVD
CVE-2026-44006Critical· 10.0
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability is fixed in 3.11.0.

▾ Midnightvm2_project · vm2EPSS 0.77%via NVD
CVE-2026-44005Critical· 10.0
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() an…

▾ Midnightvm2_project · vm2EPSS 0.83%via NVD
CVE-2026-43999Critical· 9.9
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the module builtin is allowed (including via the '*' wildcard). The module builtin exposes Node's Module._load(), which loads …

▾ Midnightvm2_project · vm2EPSS 0.97%via NVD
CVE-2026-43997Critical· 10.0
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Object, to escape the sandbox, one example would be using HostObject.getOwnPropertySymbols to…

▾ Midnightvm2_project · vm2EPSS 0.77%via NVD
CVE-2026-45411Critical· 9.8
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the return function, the value is awaited o…

▾ Midnightvm2_project · vm2EPSS 0.90%via NVD
CVE-2026-44009Critical· 9.8
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.

▾ Midnightvm2_project · vm2EPSS 0.71%via NVD
CVE-2026-44008Critical· 9.8
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but can call into this side via getter on the array prototype exposing objects of the wrong …

▾ Midnightvm2_project · vm2EPSS 0.90%via NVD
CVE-2026-6276High· 7.5PoC⚖ disputed
4mo ago

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information…

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information…

▾ Midnighthaxx · curlEPSS 0.35%via NVD
CVE-2026-5773High· 7.5PoC
4mo ago

libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connectio…

libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connectio…

▾ Midnighthaxx · curlEPSS 0.66%via NVD
CVE-2026-44579High· 7.5PoC
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through cr…

▾ Midnightvercel · next.jsEPSS 0.76%via NVD

Most-affected vendors

By CVEs published in the period.