VulnSea

Daily digest

Monday 15 June 2026

A busier-than-usual day with 91 new CVEs (recent average about 76). Of those, 6 critical and 33 high. 5 arrived with exploitation evidence or public exploit code already attached. angular was the most-affected vendor with 13.

91
New CVEs
6
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 91 published.

CVE-2026-48853Critical· 9.2PoC
3mo ago

Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flow…

Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flow…

▾ Abyssalelixir-grpc · grpcEPSS 0.78%via NVD
CVE-2026-48854High· 8.7PoC
3mo ago

Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming a large or slow-trickle unary request body. 'Elixir.G…

Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming a large or slow-trickle unary request body. 'Elixir.G…

▾ Midnightelixir-grpc · grpcEPSS 0.45%via NVD
CVE-2026-9862Critical· 9.8
3mo ago

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the …

▾ Midnightfortra · core_privileged_access_manager_serverEPSS 1.5%via NVD
CVE-2026-53633Critical· 9.8
3mo ago

Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE

Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE

▾ Midnightvitest · @vitest/browserEPSS 0.90%via GHSA
CVE-2026-48599High· 7.6PoC
3mo ago

Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting value for any path-bound field via the qu…

Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting value for any path-bound field via the qu…

▾ Midnightelixir-grpc · grpcEPSS 0.34%via NVD
CVE-2026-30120Critical· 9.8
3mo ago

Remotion: remote code execution (RCE) vulnerability

Remotion: remote code execution (RCE) vulnerability

▾ Midnightremotion · remotionEPSS 0.87%via GHSA
CVE-2026-53571HighPoC
3mo ago

vite: `server.fs.deny` bypass on Windows alternate paths

vite: `server.fs.deny` bypass on Windows alternate paths

▾ Midnightvite · viteEPSS 0.58%via GHSA
CVE-2026-54257Critical
3mo ago

Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow

Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow

▾ Midnightelectron · electronEPSS 0.43%via GHSA
CVE-2026-11417High· 7.3PoC
3mo ago

aws-cdk-lib: OS Command Injection in NodejsFunction Bundling

aws-cdk-lib: OS Command Injection in NodejsFunction Bundling

▾ Midnightaws-cdk-lib · aws-cdk-libEPSS 0.99%via GHSA
CVE-2026-30121Critical· 9.1
3mo ago

Remotion: arbitrary file write vulnerability

Remotion: arbitrary file write vulnerability

▾ Midnightremotion · remotionEPSS 0.48%via GHSA
CVE-2026-52720High· 8.8
3mo ago

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client)

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that exte…

▾ TwilightEPSS 1.2%via NVD
CVE-2026-50884High· 8.8
3mo ago

statping-ng allows attackers to escalate privileges to Administrator and access sensitive components

statping-ng allows attackers to escalate privileges to Administrator and access sensitive components

▾ Twilightstatping-ng · github.com/statping-ng/statping-ngEPSS 0.42%via OSV

Most-affected vendors

By CVEs published in the period.