VulnSea

Daily digest

Monday 18 May 2026

A quiet day: only 15 new CVEs against a recent average of about 44. Severity skewed high: 4 critical and 7 high, 73% of the total. 4 arrived with exploitation evidence or public exploit code already attached.

15
New CVEs
4
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 15 published.

CVE-2026-45829Critical· 10.0PoC
4mo ago

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_c…

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_c…

▾ AbyssalEPSS 1.0%via NVD
CVE-2026-8838Critical· 9.8PoC
4mo ago

Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client

Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. To remediate t…

▾ Abyssalredshift-connector · redshift-connectorEPSS 0.80%via NVD
CVE-2026-8836Critical· 9.8PoC
4mo ago

A vulnerability was found in lwIP up to 2.2.1

A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the argument msgAuthenticationParamet…

▾ AbyssalEPSS 1.6%via NVD
CVE-2026-25244Critical· 9.8
4mo ago

WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium

WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnerability leading to remote code execution (RCE) in test orc…

▾ Midnightopenjsf · webdriverioEPSS 3.3%via NVD
CVE-2026-20685Medium· 6.5PoC
4mo ago

An attacker in a privileged network position may be able to leak sensitive information

An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation. This issue is fixed in PCC Release 5E290.3.

▾ Twilightapple · private_cloud_computeEPSS 0.27%via NVD
CVE-2026-8851High· 8.1
4mo ago

SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated users to extract arbitrary data from the database by injecting SQL subqueries through the…

SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated users to extract arbitrary data from the database by injecting SQL subqueries through the…

▾ TwilightEPSS 0.42%via NVD
GHSA-mx64-mj3q-7prjHigh· 7.5
4mo ago

iskorotkov/avro: Denial-of-Service Vulnerability in Decoder

iskorotkov/avro: Denial-of-Service Vulnerability in Decoder

▾ Twilightiskorotkov · github.com/iskorotkov/avro/v2via OSV
CVE-2026-45727High
4mo ago

CloakBrowser: Unauthenticated path traversal via fingerprint parameter in cloakserve leads to arbitrary directory deletion

CloakBrowser: Unauthenticated path traversal via fingerprint parameter in cloakserve leads to arbitrary directory deletion

▾ Twilightcloakbrowser · cloakbrowserEPSS 0.65%via OSV
CVE-2026-45553High· 7.5
4mo ago

NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()

NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()

▾ Twilightnicegui · niceguiEPSS 0.43%via OSV
CVE-2026-45539High· 7.4
4mo ago

Microsoft APM: Symlinks under `.apm/prompts/` and `.apm/agents/` are dereferenced during `apm install`, copying host-local file contents …

Microsoft APM: Symlinks under `.apm/prompts/` and `.apm/agents/` are dereferenced during `apm install`, copying host-local file contents into the project tree

▾ Twilightapm · apmEPSS 1.1%via OSV
CVE-2026-42009High· 7.5
4mo ago

A flaw was found in gnutls

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not cor…

▾ Twilightgnu · gnutlsEPSS 1.1%via NVD
CVE-2026-4137High· 7.0
4mo ago

MLFlow Creates a Temporary File With Insecure Permissions

MLFlow Creates a Temporary File With Insecure Permissions

▾ Twilightmlflow · mlflowEPSS 0.16%via OSV

Most-affected vendors

By CVEs published in the period.