VulnSea

Daily digest

Friday 15 May 2026

A quiet day: only 7 new CVEs against a recent average of about 57. Severity skewed high: 4 high, 57% of the total. 3 arrived with exploitation evidence or public exploit code already attached.

7
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 7 that matter most of the 7 published.

CVE-2026-2652High· 8.6PoC
4mo ago

MLflow: unauthenticated access to certain FastAPI routes

MLflow: unauthenticated access to certain FastAPI routes

▾ Midnightmlflow · mlflowEPSS 1.4%via OSV
CVE-2026-46333High· 7.1PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can c…

In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can c…

▾ Midnightlinux · linux_kernelEPSS 0.51%via NVD
CVE-2026-44716High· 7.5
4mo ago

Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator

Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator

▾ Twilightpipecat-ai · pipecat-aiEPSS 0.56%via OSV
CVE-2025-54518High· 7.0
4mo ago

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.

▾ TwilightAMD · AMD EPYC™ 7002 Series ProcessorsEPSS 0.29%via NVD
CVE-2026-45736Medium· 4.4PoC
4mo ago

ws is an open source WebSocket client and server for Node.js

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability i…

▾ Twilightws_project · wsEPSS 0.68%via NVD
CVE-2026-46383Medium· 5.5
4mo ago

Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`

Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`

▾ Sunlitapm-cli · apm-cliEPSS 0.90%via OSV
CVE-2026-45106Medium· 4.6
4mo ago

Weblate: Stored HTML injection in editor search preview

Weblate: Stored HTML injection in editor search preview

▾ Sunlitweblate · weblateEPSS 0.29%via OSV

Most-affected vendors

By CVEs published in the period.