VulnSea

Daily digest

Thursday 18 June 2026

A heavy day: 186 new CVEs, well above the recent average of about 78. Severity skewed high: 36 critical and 92 high, 69% of the total. 4 arrived with exploitation evidence or public exploit code already attached. praisonai was the most-affected vendor with 48.

186
New CVEs
36
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 186 published.

CVE-2026-12569Critical· 9.8CISA KEV
3mo ago

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS…

▾ Hadalptc · flexplmEPSS 46%via NVD
CVE-2026-0755Critical· 9.80day
3mo ago

gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)

gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)

▾ Hadalgemini-mcp-tool · gemini-mcp-toolEPSS 3.5%via GHSA
CVE-2026-47103Critical· 9.8PoC
3mo ago

python-statemachine SCXML <data expr> Eval Injection

python-statemachine SCXML <data expr> Eval Injection

▾ Abyssalpython-statemachine · python-statemachineEPSS 1.4%via GHSA
GHSA-r253-r9jw-qg44Critical· 10.0
3mo ago

Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args

Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args

▾ Midnightcrawl4ai · crawl4aivia GHSA
CVE-2026-57572Critical· 10.0
3mo ago

Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args

Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args

▾ Midnightcrawl4ai · crawl4aiEPSS 0.94%via OSV
CVE-2026-47647Critical· 9.9
3mo ago

Dynamics 365 Elevation of Privilege Vulnerability

Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft Dynamics 365EPSS 0.78%via CVEORG
GHSA-x8cv-xmq7-p8xpCritical· 9.8
3mo ago

PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints

PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints

▾ Midnightpraisonaiagents · praisonaiagentsvia GHSA
GHSA-x227-pf99-vffgCritical· 9.8
3mo ago

PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in

PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in

▾ Midnightpraisonaiagents · praisonaiagentsvia GHSA
GHSA-vmmj-pfw7-fjwpCritical· 9.9
3mo ago

npm PraisonAI codeMode sandbox escape via Function constructor

npm PraisonAI codeMode sandbox escape via Function constructor

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-p75f-6fp4-p57wCritical· 9.8
3mo ago

PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai

PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-p69m-4f92-2v84Critical· 9.8
3mo ago

PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool

PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-j4hj-7hfh-g2f4Critical· 9.8
3mo ago

praisonai: recipe serve auth middleware silently disables itself when no secret is set

praisonai: recipe serve auth middleware silently disables itself when no secret is set

▾ Midnightpraisonai · praisonaivia GHSA

Most-affected vendors

By CVEs published in the period.