VulnSea

Daily digest

Thursday 11 June 2026

57 new CVEs this day, in line with the recent average. Severity skewed high: 1 critical and 30 high, 54% of the total. 9 arrived with exploitation evidence or public exploit code already attached. broadcom was the most-affected vendor with 9.

57
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 57 published.

CVE-2026-44494High· 8.7PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's depen…

▾ Midnightaxios · axiosEPSS 0.93%via NVD
CVE-2026-44492High· 8.6PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL us…

▾ Midnightaxios · axiosEPSS 0.78%via NVD
CVE-2026-48062Critical· 9.8
3mo ago

CodeIgniter4 has a validation bypass when uploading file extensions via `ext_in` rule

CodeIgniter4 has a validation bypass when uploading file extensions via `ext_in` rule

▾ Midnightcodeigniter4 · codeigniter4/frameworkEPSS 0.78%via GHSA
CVE-2026-48020HighPoC
3mo ago

Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization

Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization

▾ Midnighttraefik · github.com/traefik/traefik/v2EPSS 0.78%via GHSA
CVE-2026-44496High· 7.5PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metac…

▾ Midnightaxios · axiosEPSS 0.97%via NVD
CVE-2026-44488High· 7.5PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected …

▾ Midnightaxios · axiosEPSS 0.93%via NVD
CVE-2026-44487High· 7.5PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. Th…

▾ Midnightaxios · axiosEPSS 0.76%via NVD
CVE-2026-44486High· 7.5PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticat…

▾ Midnightaxios · axiosEPSS 0.76%via NVD
CVE-2026-44495High· 7.0PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process h…

▾ Midnightaxios · axiosEPSS 1.0%via NVD
CVE-2026-40987High· 7.1PoC
3mo ago

A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content. Affected versions: Spring Integration 7.0.0 through 7.…

A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content. Affected versions: Spring Integration 7.0.0 through 7.…

▾ Midnightvmware · spring_integrationEPSS 0.26%via NVD
CVE-2026-47162High· 8.8
3mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing br…

▾ Twilightvim · vimEPSS 0.26%via NVD
CVE-2026-40999High· 8.6
3mo ago

When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken directly from request headers without veri…

When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken directly from request headers without veri…

▾ Twilightbroadcom · spring_web_servicesEPSS 0.43%via NVD

Most-affected vendors

By CVEs published in the period.