Daily digest
Friday 12 June 2026
A busier-than-usual day with 106 new CVEs (recent average about 72). Of those, 8 critical and 44 high. 5 arrived with exploitation evidence or public exploit code already attached. typo3 was the most-affected vendor with 15.
New this day, ranked by depth score
The 12 that matter most of the 106 published.
CVE-2026-45833CriticalPoCChromaDB has a code injection vulnerability
ChromaDB has a code injection vulnerability
CVE-2026-44990Critical· 9.3PoCApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-contro…
CVE-2026-45674High· 8.7PoCNetty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS respon…
CVE-2026-54133Critical· 9.8jmespath.php: jmespath.php has CompilerRuntime code injection via unescaped function names (CVE-2026-54133)
A flaw was found in jmespath.php, a library for processing JSON documents in PHP applications. This vulnerability allows a remote attacker to execute arbitrary code by crafting a malicious JMESPath expression. The `JmesPath\CompilerRuntime…
CVE-2026-50628Critical· 9.8A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security c…
CVE-2026-49875Critical· 9.8⚖ disputedApache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgr…
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgr…
CVE-2026-50011High· 7.5PoCNetty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array elemen…
CVE-2026-12143High· 7.5PoCform-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header with…
CVE-2026-50627Critical· 9.1The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Reso…
CVE-2026-48150Critical· 9.0Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
CVE-2026-44172Critical· 9.1⚖ disputedMariaDB server is a community developed fork of MySQL server
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text pr…
CVE-2026-53822High· 8.8OpenClaw < 2026.5.18 - Command Argument Modification via Shell Wrapper Between Approval and Execution
OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command sha…
Most-affected vendors
By CVEs published in the period.