VulnSea

Weekly digest

Week 3, 2026 (12–18 Jan)

A heavy week: 196 new CVEs, well above the recent average of about 46. Severity skewed high: 12 critical and 108 high, 61% of the total. 13 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. microsoft was the most-affected vendor with 72.

196
New CVEs
12
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 196 published.

CVE-2025-25249High· 8.1CISA KEVPoC
8mo ago

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6…

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6…

Abyssalfortinet · fortiswitchmanagerEPSS 2.4%via NVD
CVE-2025-63314Critical· 10.0PoC
8mo ago

A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.

A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.

Abyssalddsn · cm3_acora_cmsEPSS 0.29%via NVD
CVE-2025-12548Critical· 9.0PoC
8mo ago

A flaw was found in Eclipse Che che-machine-exec

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unau…

AbyssalRed Hat · devspaces/code-rhel9EPSS 1.3%via NVD
CVE-2025-66177High· 8.8PoC
8mo ago

There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models

There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending spec…

MidnightEPSS 0.35%via NVD
CVE-2025-66698High· 8.6PoC
8mo ago

An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to various API endpoints.

An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to various API endpoints.

Midnightsemantic-machines · vedaEPSS 0.49%via NVD
CVE-2026-20817High· 7.8PoC
8mo ago

Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Midnightmicrosoft · windows_10_21h2EPSS 5.5%via NVD
CVE-2026-20805Medium· 5.5CISA KEV0dayPoC
8mo ago

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

Midnightmicrosoft · windows_10_1607EPSS 5.2%via NVD
CVE-2026-20820High· 7.8PoC
8mo ago

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Midnightmicrosoft · windows_10_1607EPSS 2.6%via NVD
CVE-2026-0881Critical· 10.0
8mo ago

Sandbox escape in the Messaging System component

Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.

Midnightmozilla · firefoxEPSS 0.36%via NVD
CVE-2026-22853Critical· 9.8
8mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated from hints, causing a …

Midnightfreerdp · freerdpEPSS 0.76%via NVD
CVE-2026-0879Critical· 9.8
8mo ago

Sandbox escape due to incorrect boundary conditions in the Graphics component

Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

Midnightmozilla · firefoxEPSS 0.61%via NVD
CVE-2025-68794Critical· 9.8
8mo ago

In the Linux kernel, the following vulnerability has been resolved: iomap: adjust read range correctly for non-block-aligned positions iomap_adjust_read_range() assumes that the position and length passed in are block-aligned

In the Linux kernel, the following vulnerability has been resolved: iomap: adjust read range correctly for non-block-aligned positions iomap_adjust_read_range() assumes that the position and length passed in are block-aligned. This is …

MidnightEPSS 0.59%via NVD

Most-affected vendors

By CVEs published in the period.