VulnSea

Daily digest

Tuesday 30 June 2026

56 new CVEs this day, in line with the recent average. Severity skewed high: 5 critical and 23 high, 50% of the total. 4 arrived with exploitation evidence or public exploit code already attached. fission was the most-affected vendor with 10.

56
New CVEs
5
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 56 published.

CVE-2026-50566Critical· 9.9
2mo ago

Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation

Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation

▾ Midnightfission · github.com/fission/fissionEPSS 0.51%via GHSA
CVE-2026-50564Critical· 9.9
2mo ago

Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape

Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape

▾ Midnightfission · github.com/fission/fissionEPSS 0.51%via GHSA
CVE-2026-50563Critical· 9.9
2mo ago

Fission Container Executor Function PodSpec Injection Leading to Node Escape

Fission Container Executor Function PodSpec Injection Leading to Node Escape

▾ Midnightfission · github.com/fission/fissionEPSS 0.51%via GHSA
CVE-2026-50545Critical· 9.9
2mo ago

Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover

Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover

▾ Midnightfission · github.com/fission/fissionEPSS 0.52%via GHSA
CVE-2026-37106Critical· 9.8
2mo ago

An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php

An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product i…

▾ MidnightEPSS 0.74%via NVD
CVE-2026-14164High· 7.5PoC
2mo ago

A double free issue has been identified in libarchive's RAR5 reader

A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent proc…

▾ MidnightRed Hat · libarchiveEPSS 0.73%via NVD
CVE-2026-12243High· 7.5PoC
2mo ago

nltk: NLTK: Information disclosure via path traversal vulnerability (CVE-2026-12243)

A flaw was found in NLTK. An attacker can exploit a path traversal vulnerability by providing specially crafted input to `nltk.data.load()` or `nltk.data.find()`. This allows the attacker to read arbitrary files accessible to the Python pr…

▾ MidnightRed Hat · Red Hat OpenShift AI 3.4via CSAF
CVE-2026-58014High· 7.3PoC
2mo ago

A flaw was found in GLib

A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a deni…

▾ Midnightgnome · glibEPSS 0.72%via NVD
CVE-2026-58011Medium· 6.5PoC
2mo ago

A flaw was found in GLib

A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This …

▾ Twilightgnome · glibEPSS 0.82%via NVD
CVE-2026-49824High· 8.5
2mo ago

Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook

Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook

▾ Twilightfission · github.com/fission/fissionEPSS 0.39%via GHSA
CVE-2026-48795High· 8.6
2mo ago

@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754

@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754

▾ Twilightadonisjs · @adonisjs/bodyparserEPSS 0.55%via GHSA
CVE-2026-47198High· 8.5
2mo ago

Paymenter has URL parameter injection that bypasses paid plan limits at checkout

Paymenter has URL parameter injection that bypasses paid plan limits at checkout

▾ Twilightpaymenter · paymenter/paymenterEPSS 0.40%via GHSA

Most-affected vendors

By CVEs published in the period.