VulnSea

Daily digest

Wednesday 10 June 2026

A busier-than-usual day with 85 new CVEs (recent average about 63). Severity skewed high: 7 critical and 37 high, 52% of the total. 10 arrived with exploitation evidence or public exploit code already attached. vmware was the most-affected vendor with 14.

85
New CVEs
7
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 85 published.

CVE-2026-53435High· 8.8PoC
3mo ago

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows t…

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows t…

▾ MidnightJenkins Project · JenkinsEPSS 2.2%via CVEORG
CVE-2026-48060High· 8.1PoC
3mo ago

Litestar has HTML Injection Through its CSRF Token

Litestar has HTML Injection Through its CSRF Token

▾ Midnightlitestar · litestarEPSS 0.40%via GHSA
CVE-2026-41729High· 8.1PoC
3mo ago

Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests

Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segm…

▾ Midnightvmware · spring_data_restEPSS 0.40%via NVD
CVE-2026-46529High· 7.8PoC
3mo ago

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execut…

▾ MidnightEPSS 0.41%via NVD
CVE-2026-53476Critical· 9.6
3mo ago

Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution

Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution

▾ Midnightkubev2v · github.com/kubev2v/assisted-migration-agentEPSS 0.43%via OSV
CVE-2026-53474Critical· 9.6
3mo ago

Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands

Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands

▾ Midnightkubev2v · github.com/kubev2v/migration-plannerEPSS 0.51%via OSV
CVE-2026-53471Critical· 9.6
3mo ago

Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation

Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation

▾ Midnightkubev2v · github.com/kubev2v/migration-plannerEPSS 0.51%via OSV
CVE-2026-53470Critical· 9.6
3mo ago

Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs

Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs

▾ Midnightkubev2v · github.com/kubev2v/migration-plannerEPSS 0.48%via OSV
CVE-2026-46625High· 7.5PoC
3mo ago

JavaScript Cookie is a JavaScript API for handling cookies, client-side

JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, t…

▾ Midnightjs-cookie · javascript_cookieEPSS 0.99%via NVD
CVE-2025-71329High· 7.5PoC
3mo ago

image-size: JXL and HEIF parsers allow denial of service through infinite loops

image-size: JXL and HEIF parsers allow denial of service through infinite loops

▾ Midnightimage-size · image-sizeEPSS 0.43%via GHSA
CVE-2026-11837High· 7.3PoC
3mo ago

A local privilege escalation vulnerability was found in the ansible.posix authorized_key module

A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys.…

▾ MidnightRed Hat · rhc-worker-playbookEPSS 0.16%via NVD
CVE-2026-0273High· 7.2PoC
3mo ago

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have…

▾ Midnightpaloaltonetworks · pan-osEPSS 1.3%via NVD

Most-affected vendors

By CVEs published in the period.