VulnSea

Daily digest

Wednesday 17 June 2026

A busier-than-usual day with 113 new CVEs (recent average about 97). Severity skewed high: 20 critical and 47 high, 59% of the total. 14 arrived with exploitation evidence or public exploit code already attached. open-webui was the most-affected vendor with 16.

113
New CVEs
20
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 113 published.

CVE-2026-55450Critical· 9.3PoC
3mo ago

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

▾ Abyssallangflow · langflowEPSS 1.2%via GHSA
CVE-2025-26240High· 8.4PoC
3mo ago

pdfkit: Path traversal in from_string

pdfkit: Path traversal in from_string

▾ Midnightpdfkit · pdfkitEPSS 0.39%via GHSA
CVE-2026-55200High· 8.1PoC
3mo ago

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessiv…

▾ Midnightlibssh2 · libssh2EPSS 0.83%via NVD
CVE-2026-54415High· 8.1PoC
3mo ago

Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over…

Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over…

▾ MidnightEPSS 0.49%via NVD
CVE-2026-42530High· 8.1PoC
3mo ago

NGINX Open Source has a vulnerability in the ngx_http_v3_module module

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially …

▾ Midnightf5 · nginx_gateway_fabricEPSS 1.1%via NVD
CVE-2026-42055High· 8.1PoC
3mo ago

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, …

▾ Midnightf5 · dosEPSS 2.4%via NVD
GHSA-82fg-2r99-h7v6Critical· 10.0
3mo ago

Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass

Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass

▾ Midnightpicklescan · picklescanvia GHSA
CVE-2026-25470Critical· 10.0
3mo ago

Unauthenticated Remote Code Execution (RCE) in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.47 versions.

Unauthenticated Remote Code Execution (RCE) in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.47 versions.

▾ MidnightACPT · ACPT (Pro) - Custom Post Types Plugin for WordPressEPSS 0.86%via NVD
GHSA-rmpp-8wf5-xx5qCritical· 9.8
3mo ago

Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing

Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing

▾ Midnightpicklescan · picklescanvia GHSA
GHSA-j6c9-qvp8-699fCritical· 9.8
3mo ago

Duplicate Advisory: picklescan missing detection by simple obfuscation of a `builtins.eval` call

Duplicate Advisory: picklescan missing detection by simple obfuscation of a `builtins.eval` call

▾ Midnightpicklescan · picklescanvia GHSA
GHSA-7f79-rvx6-vxc4Critical· 9.8
3mo ago

Duplicate Advisory: Picklescan does not block ctypes

Duplicate Advisory: Picklescan does not block ctypes

▾ Midnightpicklescan · picklescanvia GHSA
GHSA-6v84-v468-3c7fCritical· 9.8
3mo ago

Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs

Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs

▾ Midnightpicklescan · picklescanvia GHSA

Most-affected vendors

By CVEs published in the period.