VulnSea

Weekly digest

Week 2, 2026 (5–11 Jan)

A heavy week: 70 new CVEs, well above the recent average of about 41. Of those, 4 critical and 30 high. 11 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. aiohttp was the most-affected vendor with 6.

70
New CVEs
4
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 70 published.

CVE-2025-61686Critical· 9.1PoC
8mo ago

React Router is a router for React

React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if createFileSessionStorage() is being used from @react-router/…

Abyssalshopify · react-router/nodeEPSS 18%via NVD
CVE-2025-68493High· 8.1PoC
8mo ago

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes th…

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes th…

Midnightapache · strutsEPSS 43%via NVD
CVE-2025-12543Critical· 9.6PoC
8mo ago

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containi…

Abyssalredhat · build_of_apache_camelEPSS 1.4%via NVD
CVE-2025-69264High· 8.8PoC
8mo ago

pnpm is a package manager

pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution disabled by default". Wh…

Midnightpnpm · pnpmEPSS 1.0%via NVD
CVE-2025-70974Critical· 10.0
8mo ago

Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class

Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of …

MidnightEPSS 0.77%via NVD
CVE-2025-59057High· 7.6PoC
8mo ago

React Router is a router for React

React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating s…

Midnightshopify · react-routerEPSS 0.51%via NVD
CVE-2026-22189Critical· 9.8
8mo ago

The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains a stack-based buffer overflow vulnerability due to use of an unbounded sprintf() call with attacker-controlled input

The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains a stack-based buffer overflow vulnerability due to use of an unbounded sprintf() call with attacker-controlled input. When constructing glyph filenames, egg-…

Midnightcmu · panda3dEPSS 0.51%via NVD
CVE-2025-68428High· 7.5PoC
8mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusion/path traversal. If given the possibility to pass unsani…

Midnightparall · jspdfEPSS 2.2%via NVD
CVE-2025-65518High· 7.5PoC
8mo ago

Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition

Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_password.php endpoint, where a crafted request containing a malicious payload can cause the affected…

Midnightwebpros · plesk_obsidianEPSS 0.62%via NVD
CVE-2025-69263High· 7.5PoC
8mo ago

pnpm is a package manager

pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve different content on each install, even when…

MidnightRed Hat · pnpmEPSS 0.43%via NVD
CVE-2025-9222High· 8.7
8mo ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploitin…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploitin…

Twilightgitlab · gitlabEPSS 0.43%via NVD
CVE-2026-0719High· 8.6
8mo ago

A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication

A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When processing extremely long passwords, an internal size calculation can overflow du…

TwilightEPSS 0.62%via NVD

Most-affected vendors

By CVEs published in the period.