VulnSea

Daily digest

Friday 29 May 2026

A heavy day: 58 new CVEs, well above the recent average of about 25. Severity skewed high: 13 critical and 26 high, 67% of the total. 3 arrived with exploitation evidence or public exploit code already attached. praisonai-platform was the most-affected vendor with 6.

58
New CVEs
13
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 58 published.

CVE-2026-46372High· 8.5PoC
4mo ago

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern exposes /api/search/searx…

▾ MidnightEPSS 1.0%via NVD
CVE-2026-45661Critical· 9.9
4mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitrary files to the filesystem during app…

▾ MidnightEPSS 1.0%via NVD
CVE-2026-45633Critical· 9.9
4mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated an…

▾ MidnightEPSS 1.9%via NVD
CVE-2026-45632Critical· 9.9
4mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, update, run, or delete schedules belongi…

▾ MidnightEPSS 0.45%via NVD
CVE-2026-45631Critical· 10.0
4mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-secret-123456789") lets an unauthenticated attacker forge email verification JWTs, trigger…

▾ MidnightEPSS 0.68%via NVD
CVE-2026-45629Critical· 9.9
4mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any organization member to execute arbitrary system commands on …

▾ MidnightEPSS 1.3%via NVD
CVE-2026-44962Critical· 9.9
4mo ago

Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization

Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged u…

▾ MidnightEPSS 0.55%via NVD
CVE-2026-47393Critical· 9.8
4mo ago

PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default

PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default

▾ Midnightpraisonai · praisonaiEPSS 0.78%via OSV
CVE-2026-45700Critical· 9.8
4mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c, freerdp_bitmap_decompress_plan…

▾ Midnightfreerdp · freerdpEPSS 0.78%via NVD
CVE-2026-44649Critical· 9.8
4mo ago

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Auth…

▾ MidnightEPSS 0.29%via NVD
CVE-2026-46385High· 7.5PoC
4mo ago

iskorotkov/avro is a fast Go Avro codec

iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-controlled block-count value without checking the underlying reader's error state inside the loop body. Reader.ReadBlockHea…

▾ Midnightiskorotkov · avroEPSS 0.88%via NVD
CVE-2026-45628Critical· 9.6
4mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template literals and executes them via child_process.exec() (which runs through /bin/sh -c). User-s…

▾ MidnightEPSS 0.39%via NVD

Most-affected vendors

By CVEs published in the period.