VulnSea

Weekly digest

Week 6, 2026 (2–8 Feb)

75 new CVEs this week, in line with the recent average. Of those, 5 critical and 27 high. 7 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. Linux was the most-affected vendor with 11.

75
New CVEs
5
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 75 published.

CVE-2026-22778Critical· 9.8PoC
7mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a hea…

Abyssalvllm · vllmEPSS 3.8%via NVD
CVE-2025-64712Critical· 9.8
7mo ago

Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write

Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write

Midnightunstructured · unstructuredEPSS 0.63%via OSV
CVE-2026-1709Critical· 9.4
7mo ago

A flaw was found in Keylime

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network ac…

Midnightkeylime · keylimeEPSS 5.5%via NVD
GHSA-4f84-67cv-qrv3Critical
7mo ago

A single post-release of dydx-v4-client contained obfuscated multi-stage loader

A single post-release of dydx-v4-client contained obfuscated multi-stage loader

Midnightdydx-v4-client · dydx-v4-clientvia OSV
CVE-2026-25481Critical
7mo ago

Langroid has WAF Bypass Leading to RCE in TableChatAgent

Langroid has WAF Bypass Leading to RCE in TableChatAgent

Midnightlangroid · langroidEPSS 0.66%via OSV
CVE-2026-25521High· 8.8
7mo ago

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype pollution vulnerability exists in locutus. Despite a previous fix that attempted to mitig…

Twilightlocutus · locutusEPSS 0.29%via NVD
CVE-2026-24514Medium· 6.5PoC
7mo ago

ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling

ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling

Twilightingress-nginx · k8s.io/ingress-nginxEPSS 0.48%via OSV
CVE-2026-1761High· 8.6
7mo ago

A flaw was found in libsoup

A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted m…

TwilightEPSS 1.0%via NVD
CVE-2026-25580High· 8.6
7mo ago

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) vulnerability exists in Pydantic AI's URL download functionality. When …

Twilightpydantic · pydantic_aiEPSS 0.60%via NVD
CVE-2026-2015Medium· 6.3PoC
7mo ago

A weakness has been identified in Portabilis i-Educar up to 2.10

A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the component Final Status Import. Executing a manipulation of the argument school_id can lead …

Twilightportabilis · i-educarEPSS 0.31%via NVD
CVE-2025-61732High· 8.6
7mo ago

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

Twilightgolang · goEPSS 0.48%via NVD
CVE-2026-0599High· 7.5
7mo ago

Hugging Face Text Generation Inference vulnerable to Uncontrolled Resource Consumption

Hugging Face Text Generation Inference vulnerable to Uncontrolled Resource Consumption

Twilighttext-generation · text-generationEPSS 28%via OSV

Most-affected vendors

By CVEs published in the period.