VulnSea

Daily digest

Friday 5 June 2026

26 new CVEs this day, in line with the recent average. Of those, 11 high. One arrived with exploitation evidence or public exploit code already attached. x.org was the most-affected vendor with 9.

26
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 26 published.

CVE-2026-41567High· 7.2PoC
3mo ago

Moby is an open source container framework

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, …

▾ Midnightmoby · moby/v2/daemonEPSS 0.17%via NVD
CVE-2026-47419High· 8.3
3mo ago

praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR

praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR

▾ Twilightpraisonai-platform · praisonai-platformEPSS 0.39%via OSV
CVE-2026-50264High· 7.8
3mo ago

An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat

An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds he…

▾ Twilightx.org · x_serverEPSS 0.20%via NVD
CVE-2026-50261High· 7.8
3mo ago

A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter()

A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while chang…

▾ Twilightx.org · x_serverEPSS 0.20%via NVD
CVE-2026-50260High· 7.8
3mo ago

A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter()

A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client…

▾ Twilightx.org · x_serverEPSS 0.20%via NVD
CVE-2026-50259High· 7.8
3mo ago

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at…

▾ Twilightx.org · x_serverEPSS 0.22%via NVD
CVE-2026-50258High· 7.8
3mo ago

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to Xkb…

▾ Twilightx.org · x_serverEPSS 0.22%via NVD
CVE-2026-50257High· 7.8
3mo ago

A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence()

A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to se…

▾ Twilightx.org · x_serverEPSS 0.20%via NVD
CVE-2026-50256High· 7.8
3mo ago

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The ser…

▾ Twilightx.org · x_serverEPSS 0.21%via NVD
CVE-2026-11332High· 7.8
3mo ago

A flaw was found in ansible-core

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can in…

▾ TwilightRed Hat · ansible-coreEPSS 0.22%via NVD
CVE-2026-47261High· 7.5
3mo ago

wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction

wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction

▾ Twilightwasmtime-wasi · wasmtime-wasiEPSS 0.50%via OSV
CVE-2026-37737Medium· 6.5
3mo ago

sanic-cors contains an improper regular expression in the try_match() function

sanic-cors contains an improper regular expression in the try_match() function

▾ Sunlitsanic-cors · sanic-corsEPSS 0.24%via OSV

Most-affected vendors

By CVEs published in the period.