VulnSea

Daily digest

Tuesday 2 June 2026

26 new CVEs this day, in line with the recent average. Of those, 1 critical and 7 high. 9 arrived with exploitation evidence or public exploit code already attached. elixir-tesla was the most-affected vendor with 5.

26
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 26 published.

CVE-2026-47117Critical· 9.8PoC
3mo ago

OpenMed vulnerable to remote code injection through privacy-filter model loading path

OpenMed vulnerable to remote code injection through privacy-filter model loading path

▾ Abyssalopenmed · openmedEPSS 1.3%via OSV
CVE-2026-30652High· 8.8
3mo ago

A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a

A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbi…

▾ Twilightvivotek · fd8136_firmwareEPSS 0.76%via NVD
CVE-2026-27145Medium· 6.5PoC
3mo ago

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SA…

▾ TwilightGo standard library · crypto/x509EPSS 0.59%via NVD
CVE-2026-1784High· 8.8
3mo ago

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a contro…

▾ Twilightredhat · openshift_container_platformEPSS 0.19%via NVD
RUSTSEC-2026-0279High· 8.1
3mo ago

Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution

Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution

▾ Twilightrojo · rojovia OSV
CVE-2026-48597Medium· 5.9PoC⚖ disputed
3mo ago

Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesla.Adapter.Mint. Tesla.Adapter.Mint.open_conn/2 converts the URL scheme of every outgoing …

Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesla.Adapter.Mint. Tesla.Adapter.Mint.open_conn/2 converts the URL scheme of every outgoing …

▾ Twilightelixir-tesla · teslaEPSS 0.63%via NVD
CVE-2026-48595Medium· 5.9PoC⚖ disputed
3mo ago

Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party origin on cross-origin redirects. Tesla.Middleware.FollowRedirects strips security-sensitive headers on cross-origin re…

Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party origin on cross-origin redirects. Tesla.Middleware.FollowRedirects strips security-sensitive headers on cross-origin re…

▾ Twilightelixir-tesla · teslaEPSS 0.67%via NVD
CVE-2026-43965Medium· 5.6PoC
3mo ago

Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/packages/packages.toml content. Package keys read from build/packages/packages.toml by LocalPackages::read_from_disc a…

Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/packages/packages.toml content. Package keys read from build/packages/packages.toml by LocalPackages::read_from_disc a…

▾ TwilightGleam · gleamEPSS 0.19%via NVD
CVE-2026-48594High· 7.5
3mo ago

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of service via decompression bomb in HTTP response bodies. When Tesla.Middleware.DecompressResponse or Tesla.Middleware…

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of service via decompression bomb in HTTP response bodies. When Tesla.Middleware.DecompressResponse or Tesla.Middleware…

▾ Twilightelixir-tesla · teslaEPSS 0.70%via NVD
CVE-2026-42504High· 7.5
3mo ago

Quadratic complexity in WordDecoder.DecodeHeader in mime

Quadratic complexity in WordDecoder.DecodeHeader in mime

▾ Twilightstdlib · stdlibEPSS 0.56%via OSV
CVE-2026-3514High· 7.5
3mo ago

Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready'

Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready'

▾ Twilightprefect · prefectEPSS 0.63%via OSV
CVE-2026-42795Medium· 5.1PoC
3mo ago

Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball. The file collection helpers (gleam_files, native_files, private_files) in compiler-cli/…

Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball. The file collection helpers (gleam_files, native_files, private_files) in compiler-cli/…

▾ TwilightGleam · gleamEPSS 0.17%via NVD

Most-affected vendors

By CVEs published in the period.