VulnSea

Daily digest

Wednesday 1 July 2026

A busier-than-usual day with 129 new CVEs (recent average about 83). Severity skewed high: 14 critical and 56 high, 54% of the total. 5 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. surrealdb was the most-affected vendor with 29.

129
New CVEs
14
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 129 published.

MAL-2026-6724Critical⚠ Exploited
2mo ago

Malicious code in starlette-healthcheck (PyPI)

Malicious code in starlette-healthcheck (PyPI)

▾ Abyssalstarlette-healthcheck · starlette-healthcheckvia OSV
CVE-2026-14382Critical· 9.6PoC
2mo ago

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Abyssalgoogle · chromeEPSS 0.34%via NVD
CVE-2026-57516High· 8.8PoC
2mo ago

Ray < 2.56.0 Unsafe Deserialization RCE via WebDataset Reader

Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution by supplying a malicious tar archive to the read_webdataset() function. The _default_dec…

▾ MidnightAnyscale, Inc · RayEPSS 0.86%via CVEORG
CVE-2026-58592High· 8.3PoC
2mo ago

Ladybird before commit 2f9dc7e contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader

Ladybird before commit 2f9dc7e contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaScript function is imported into a WebAssembly module via the ESM path, WebAssemblyModule.cpp pa…

▾ MidnightLadybirdBrowser · LadybirdEPSS 0.55%via NVD
CVE-2026-46680High· 7.8PoC
2mo ago

containerd is an open-source container runtime

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leadi…

▾ Midnightlinuxfoundation · containerdEPSS 0.16%via NVD
CVE-2026-44935Critical· 9.9
2mo ago

Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer

Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer

▾ Midnightrancher · github.com/rancher/fleetEPSS 0.49%via GHSA
CVE-2026-53355Critical· 9.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB connection teardown path is written so it can run during partial startup and on repeated shutdown attempts

In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB connection teardown path is written so it can run during partial startup and on repeated shutdown attempts. It uses …

▾ MidnightEPSS 0.42%via NVD
CVE-2026-53943Critical· 9.6
2mo ago

Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header

Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header

▾ Midnightghost · ghostEPSS 0.45%via GHSA
CVE-2026-44939Critical· 9.6
2mo ago

Rancher vulnerable to command injection through unsanitized YAML parameter

Rancher vulnerable to command injection through unsanitized YAML parameter

▾ Midnightrancher · github.com/rancher/rancherEPSS 1.3%via GHSA
CVE-2026-14411Critical· 9.6
2mo ago

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-14405Critical· 9.6
2mo ago

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

▾ Midnightgoogle · chromeEPSS 0.50%via NVD
CVE-2026-14398Critical· 9.6
2mo ago

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

▾ Midnightgoogle · chromeEPSS 0.34%via NVD

Most-affected vendors

By CVEs published in the period.