VulnSea

Weekly digest

Week 9, 2026 (23 Feb – 1 Mar)

67 new CVEs this week, in line with the recent average. Of those, 7 critical and 19 high. 11 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. arcinfo was the most-affected vendor with 7.

67
New CVEs
7
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 67 published.

CVE-2026-27577Critical· 9.9PoC
6mo ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and patched following CVE-2025-68613. An authenticated user w…

Abyssaln8n · n8nEPSS 10.0%via NVD
CVE-2026-27941Critical· 9.9PoC
6mo ago

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repo…

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_target` event while checking out and executing untrusted code from fork…

Abyssalopenlit · openlitEPSS 0.40%via OSV
CVE-2026-27727Critical· 9.8PoC
6mo ago

mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked…

mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked…

Abyssalmchange · mchange_commons_javaEPSS 0.81%via NVD
CVE-2026-27606Critical· 9.8PoC
6mo ago

Rollup is a module bundler for JavaScript

Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure …

Abyssalrollupjs · rollupEPSS 1.5%via NVD
CVE-2026-27483High· 8.8PoC
7mo ago

MindsDB: Path Traversal in /api/files Leading to Remote Code Execution

MindsDB: Path Traversal in /api/files Leading to Remote Code Execution

Midnightmindsdb · mindsdbEPSS 11%via OSV
CVE-2026-26331High· 8.8PoC
7mo ago

yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option

yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option

Midnightyt-dlp · yt-dlpEPSS 1.6%via OSV
CVE-2026-25747High· 8.8PoC
7mo ago

Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without a…

Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without a…

Midnightapache · camelEPSS 0.98%via NVD
CVE-2026-21660Critical· 9.8
6mo ago

A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, an…

A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, an…

Midnightjohnsoncontrols · frick_controls_quantum_hd_firmwareEPSS 0.23%via NVD
CVE-2026-2771Critical· 9.8
7mo ago

Undefined behavior in the DOM: Core & HTML component

Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

Midnightmozilla · firefoxEPSS 0.48%via NVD
CVE-2026-28231Critical· 9.1
6mo ago

pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the en…

pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path buffer validation of `_pillow_heif.c` allows an attacker to bypass bounds checks by provid…

Midnightpi-heif · pi-heifEPSS 0.63%via OSV
CVE-2026-27696High· 8.6
6mo ago

changedetection.io is Vulnerable to SSRF via Watch URLs

changedetection.io is Vulnerable to SSRF via Watch URLs

Twilightchangedetection-io · changedetection-ioEPSS 0.45%via OSV
CVE-2026-27645Medium· 6.1PoC
6mo ago

changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response

changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response

Twilightchangedetection-io · changedetection-ioEPSS 0.45%via OSV

Most-affected vendors

By CVEs published in the period.