VulnSea

Weekly digest

Week 20, 2026 (11–17 May)

A busier-than-usual week with 314 new CVEs (recent average about 225). Severity skewed high: 21 critical and 161 high, 58% of the total. 31 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. adobe was the most-affected vendor with 38.

314
New CVEs
21
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 314 published.

CVE-2026-42945High· 8.1PoC
4mo ago

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expre…

Midnightf5 · dosEPSS 68%via NVD
CVE-2026-44578High· 8.6PoC
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted…

Midnightvercel · next.jsEPSS 39%via NVD
CVE-2026-2652High· 8.6PoC
4mo ago

MLflow: unauthenticated access to certain FastAPI routes

MLflow: unauthenticated access to certain FastAPI routes

Midnightmlflow · mlflowEPSS 21%via OSV
CVE-2026-40217High· 8.8PoC
4mo ago

LiteLLM has a sandbox escape in custom-code guardrail

LiteLLM has a sandbox escape in custom-code guardrail

Midnightlitellm · litellmEPSS 15%via OSV
CVE-2026-20224High· 8.6PoC
4mo ago

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have va…

MidnightEPSS 1.0%via NVD
CVE-2026-28995High· 8.8PoC
4mo ago

A logic issue was addressed with improved restrictions

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A…

Midnightapple · ipadosEPSS 0.12%via NVD
CVE-2026-45401High· 8.5PoC
4mo ago

Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)

Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)

Midnightopen-webui · open-webuiEPSS 0.30%via OSV
CVE-2026-44338High· 7.3PoC
4mo ago

PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution

PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution

Midnightpraisonai · praisonaiEPSS 29%via OSV
CVE-2026-40369High· 7.8PoC
4mo ago

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

MidnightEPSS 4.7%via NVD
CVE-2026-44006Critical· 10.0
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability is fixed in 3.11.0.

Midnightvm2_project · vm2EPSS 0.81%via NVD
CVE-2026-44005Critical· 10.0
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() an…

Midnightvm2_project · vm2EPSS 0.83%via NVD
CVE-2026-43999Critical· 9.9
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the module builtin is allowed (including via the '*' wildcard). The module builtin exposes Node's Module._load(), which loads …

Midnightvm2_project · vm2EPSS 0.97%via NVD

Most-affected vendors

By CVEs published in the period.