VulnSea

Daily digest

Friday 12 June 2026

A busier-than-usual day with 106 new CVEs (recent average about 72). Of those, 8 critical and 44 high. 5 arrived with exploitation evidence or public exploit code already attached. typo3 was the most-affected vendor with 15.

106
New CVEs
8
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 106 published.

CVE-2026-45833CriticalPoC
3mo ago

ChromaDB has a code injection vulnerability

ChromaDB has a code injection vulnerability

▾ Abyssalchromadb · chromadbEPSS 0.63%via OSV
CVE-2026-44990Critical· 9.3PoC
3mo ago

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-contro…

▾ Abyssalapostrophecms · sanitize-htmlEPSS 0.69%via NVD
CVE-2026-45674High· 8.7PoC
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS respon…

▾ Midnightnetty · nettyEPSS 0.36%via NVD
CVE-2026-54133Critical· 9.8
3mo ago

jmespath.php: jmespath.php has CompilerRuntime code injection via unescaped function names (CVE-2026-54133)

A flaw was found in jmespath.php, a library for processing JSON documents in PHP applications. This vulnerability allows a remote attacker to execute arbitrary code by crafting a malicious JMESPath expression. The `JmesPath\CompilerRuntime…

▾ MidnightRed Hat · mtdowling/jmespath.phpEPSS 0.56%via CSAF
CVE-2026-50628Critical· 9.8
3mo ago

A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address

A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security c…

▾ Midnightapache · cxfEPSS 1.0%via NVD
CVE-2026-49875Critical· 9.8⚖ disputed
3mo ago

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgr…

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgr…

▾ Midnightapache · cxfEPSS 0.81%via NVD
CVE-2026-50011High· 7.5PoC
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array elemen…

▾ Midnightnetty · nettyEPSS 0.85%via NVD
CVE-2026-12143High· 7.5PoC
3mo ago

form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)

form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header with…

▾ Midnightform-data · form-dataEPSS 0.67%via CVEORG
CVE-2026-50627Critical· 9.1
3mo ago

The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens

The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Reso…

▾ Midnightapache · cxfEPSS 0.78%via NVD
CVE-2026-48150Critical· 9.0
3mo ago

Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign

Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign

▾ Midnightbudibase · @budibase/serverEPSS 0.47%via GHSA
CVE-2026-44172Critical· 9.1⚖ disputed
3mo ago

MariaDB server is a community developed fork of MySQL server

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text pr…

▾ Midnightmariadb · mariadbEPSS 1.0%via NVD
CVE-2026-53822High· 8.8
3mo ago

OpenClaw < 2026.5.18 - Command Argument Modification via Shell Wrapper Between Approval and Execution

OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command sha…

▾ TwilightOpenClaw · OpenClawEPSS 2.0%via CVEORG

Most-affected vendors

By CVEs published in the period.