VulnSea

Daily digest

Monday 22 June 2026

83 new CVEs this day, in line with the recent average. Severity skewed high: 6 critical and 36 high, 51% of the total. 5 arrived with exploitation evidence or public exploit code already attached. budibase was the most-affected vendor with 7.

83
New CVEs
6
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 83 published.

CVE-2026-11746Critical· 9.4PoC
3mo ago

A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret

A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. …

▾ AbyssalLY Corporation · Central DogmaEPSS 0.23%via NVD
CVE-2026-48746Critical· 9.1PoC
3mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API Authenti…

▾ Abyssalvllm · vllmEPSS 1.2%via NVD
CVE-2026-11745High· 8.8PoC
3mo ago

A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-t…

A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-t…

▾ MidnightLY Corporation · Central DogmaEPSS 0.22%via NVD
CVE-2026-44179Critical· 9.9
3mo ago

xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro

xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro

▾ Midnightxwiki · com.xwiki.pro:xwiki-pro-macrosvia GHSA
CVE-2025-67303High· 7.5PoC
3mo ago

ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)

ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)

▾ Midnightcomfyui-manager · comfyui-managerEPSS 1.4%via GHSA
CVE-2026-54352Critical· 9.6
3mo ago

Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload

Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload

▾ Midnightbudibase · @budibase/serverEPSS 0.49%via GHSA
CVE-2026-54293High· 7.5PoC
3mo ago

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to path tr…

▾ Midnightnltk · nltkEPSS 0.63%via NVD
CVE-2026-33646Critical· 9.6
3mo ago

Mise Vulnerable to Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)

Mise Vulnerable to Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)

▾ Midnightmise · miseEPSS 0.69%via GHSA
CVE-2026-12249Critical· 9.0
3mo ago

Canonical ADSys Uses a Less Trusted Source

Canonical ADSys Uses a Less Trusted Source

▾ Midnightubuntu · github.com/ubuntu/adsysEPSS 0.14%via OSV
CVE-2026-52798High· 8.9
3mo ago

Gogs has Stored XSS in `.ipynb` Preview

Gogs has Stored XSS in `.ipynb` Preview

▾ Twilightgogs · gogs.io/gogsEPSS 0.43%via GHSA
CVE-2026-54099High· 8.8
3mo ago

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not rej…

▾ Twilightredhat · openshift_container_platformEPSS 0.11%via NVD
CVE-2026-54353High· 8.5
3mo ago

@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation

@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation

▾ Twilightbudibase · @budibase/backend-coreEPSS 0.21%via GHSA

Most-affected vendors

By CVEs published in the period.