Daily digest
Friday 15 May 2026
A quiet day: only 7 new CVEs against a recent average of about 57. Severity skewed high: 4 high, 57% of the total. 3 arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 7 that matter most of the 7 published.
CVE-2026-2652High· 8.6PoCMLflow: unauthenticated access to certain FastAPI routes
MLflow: unauthenticated access to certain FastAPI routes
CVE-2026-46333High· 7.1PoCIn the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can c…
In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can c…
CVE-2026-44716High· 7.5Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator
Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator
CVE-2025-54518High· 7.0Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.
Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.
CVE-2026-45736Medium· 4.4PoCws is an open source WebSocket client and server for Node.js
ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability i…
CVE-2026-46383Medium· 5.5Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`
Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`
CVE-2026-45106Medium· 4.6Weblate: Stored HTML injection in editor search preview
Weblate: Stored HTML injection in editor search preview
Most-affected vendors
By CVEs published in the period.