VulnSea

Weekly digest

Week 8, 2026 (16–22 Feb)

57 new CVEs this week, in line with the recent average. Severity skewed high: 7 critical and 29 high, 63% of the total. 17 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. codeastro was the most-affected vendor with 3.

57
New CVEs
7
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 57 published.

CVE-2026-2033High· 8.10day
7mo ago

MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability

MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability

Abyssalmlflow · mlflowEPSS 1.7%via OSV
CVE-2025-70152Critical· 9.8PoC
7mo ago

code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php

code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly c…

Abyssalfabian · scholars_tracking_systemEPSS 0.45%via NVD
CVE-2025-70150Critical· 9.8PoC
7mo ago

CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.

CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.

Abyssalcodeastro · membership_management_systemEPSS 0.66%via NVD
CVE-2025-70149Critical· 9.8PoC
7mo ago

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.

Abyssalcodeastro · membership_management_systemEPSS 0.39%via NVD
CVE-2026-2635High· 7.30day⚖ disputed
7mo ago

MLflow Use of Default Password Authentication Bypass Vulnerability

MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. T…

AbyssalMLflow · MLflowEPSS 0.98%via NVD
CVE-2025-70141Critical· 9.4PoC
7mo ago

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php bas…

Abyssaloretnom23 · customer_support_systemEPSS 0.69%via NVD
CVE-2026-25896Critical· 9.3PoC⚖ disputed
7mo ago

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard…

Abyssalnaturalintelligence · fast-xml-parserEPSS 0.47%via NVD
CVE-2025-70146Critical· 9.1PoC
7mo ago

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting reco…

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting reco…

Abyssalprojectworlds · online_time_table_generatorEPSS 0.57%via NVD
CVE-2025-70151High· 8.8PoC
7mo ago

code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload

code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-acce…

Midnightfabian · scholars_tracking_systemEPSS 0.70%via NVD
CVE-2026-26731High· 8.8PoC
7mo ago

TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function.

TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function.

Midnighttotolink · a3002ru_firmwareEPSS 0.50%via NVD
CVE-2026-25940High· 8.1PoC
7mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass u…

Midnightparall · jspdfEPSS 0.43%via NVD
CVE-2026-25755High· 8.1PoC
7mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows an attacker to inject arbitrary PDF objects into the generated document. By crafting a payload that escapes the …

Midnightparall · jspdfEPSS 0.85%via NVD

Most-affected vendors

By CVEs published in the period.