VulnSea

Weekly digest

Week 5, 2026 (26 Jan – 1 Feb)

53 new CVEs this week, in line with the recent average. Severity skewed high: 3 critical and 26 high, 55% of the total. 8 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. Linux was the most-affected vendor with 8.

53
New CVEs
3
Critical
2
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 53 published.

CVE-2026-21509High· 7.8CISA KEV0dayPoC
7mo ago

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

Abyssalmicrosoft · 365_appsEPSS 73%via NVD
CVE-2025-15467High· 8.8PoC
7mo ago

Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, …

Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, …

Midnightopenssl · opensslEPSS 48%via NVD
CVE-2026-24486High· 8.6PoC
7mo ago

Python-Multipart is a streaming multipart parser for Python

Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write …

Midnightfastapiexpert · python-multipartEPSS 2.2%via NVD
CVE-2025-24293High· 8.1PoC
7mo ago

# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three me…

# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three me…

MidnightEPSS 5.4%via NVD
CVE-2026-21721High· 8.1PoC
7mo ago

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on ot…

Midnightgrafana · grafanaEPSS 0.69%via NVD
CVE-2025-61140Critical· 9.8
7mo ago

The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.

The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.

Midnightdchester · jsonpathEPSS 0.44%via NVD
CVE-2020-36939High· 7.5PoC
7mo ago

Cassandra Web - Remote File Read

Cassandra Web - Remote File Read

Midnightcassandra-web · cassandra-webEPSS 2.6%via GHSA
CVE-2026-40035Critical
7mo ago

Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)

Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)

Midnightdfir-unfurl · dfir-unfurlEPSS 0.56%via OSV
CVE-2026-24874Critical· 9.1
7mo ago

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before 2025.12.30.

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before 2025.12.30.

MidnightEPSS 0.26%via NVD
CVE-2026-24747High· 8.8
7mo ago

PyTorch is a Python package that provides tensor computation

PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.l…

Twilightlinuxfoundation · pytorchEPSS 0.72%via NVD
CVE-2026-24869High· 8.8
7mo ago

Use-after-free in the Layout: Scrolling and Overflow component

Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability was fixed in Firefox 147.0.2.

Twilightmozilla · firefoxEPSS 0.24%via NVD
CVE-2025-14459High· 8.5
7mo ago

A flaw was found in KubeVirt Containerized Data Importer (CDI)

A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolumeClaims (PVCs) from unauthorized namespaces, resulting in unauthorized access to data via the DataImportCron PVC sou…

TwilightEPSS 0.35%via NVD

Most-affected vendors

By CVEs published in the period.