VulnSea

Daily digest

Sunday 21 June 2026

A quiet day: only 18 new CVEs against a recent average of about 97. Severity skewed high: 2 critical and 7 high, 50% of the total. 2 arrived with exploitation evidence or public exploit code already attached. litellm was the most-affected vendor with 9.

18
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 18 published.

CVE-2026-56265Critical· 9.8PoC
3mo ago

Crawl4AI: authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server

Crawl4AI: authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server

▾ Abyssalcrawl4ai · crawl4aiEPSS 2.6%via GHSA
CVE-2025-71348High· 8.1PoC
3mo ago

picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods

picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but execut…

▾ Midnightmmaitre314 · picklescanEPSS 0.55%via NVD
GHSA-24r3-p3x6-cqvxCritical· 9.6
3mo ago

Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
GHSA-qvp4-q2p5-22ggHigh· 8.1
3mo ago

Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config

Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config

▾ Twilightpicklescan · picklescanvia GHSA
GHSA-fcqg-3mwf-cfcfHigh· 8.1
3mo ago

Duplicate Advisory: Picklescan is missing detection when calling built-in Python cProfile.runctx

Duplicate Advisory: Picklescan is missing detection when calling built-in Python cProfile.runctx

▾ Twilightpicklescan · picklescanvia GHSA
GHSA-8mc5-7w9m-fqv6High· 8.1
3mo ago

Duplicate Advisory: Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand

Duplicate Advisory: Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand

▾ Twilightpicklescan · picklescanvia GHSA
GHSA-fh2f-24rh-r2vqHigh
3mo ago

Duplicate Advisory: Picklescan missing detection when calling built-in python library function timeit.timeit()

Duplicate Advisory: Picklescan missing detection when calling built-in python library function timeit.timeit()

▾ Twilightpicklescan · picklescanvia GHSA
CVE-2026-12795High· 7.3
3mo ago

LiteLLM: SSO Debug Flow Has Improper Authentication

LiteLLM: SSO Debug Flow Has Improper Authentication

▾ Twilightlitellm · litellmEPSS 0.80%via OSV
CVE-2026-12773High· 7.3
3mo ago

LiteLLM: MCP Proxy Has Improper Authentication

LiteLLM: MCP Proxy Has Improper Authentication

▾ Twilightlitellm · litellmEPSS 1.0%via OSV
CVE-2026-12798Medium· 6.3
3mo ago

BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader

BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader

▾ Sunlitlitellm · litellmEPSS 0.40%via OSV
CVE-2026-12797Medium· 6.3
3mo ago

BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints

BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints

▾ Sunlitlitellm · litellmEPSS 0.40%via OSV
CVE-2026-12796Medium· 6.3
3mo ago

BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens

BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens

▾ Sunlitlitellm · litellmEPSS 0.57%via OSV

Most-affected vendors

By CVEs published in the period.