VulnSea

Weekly digest

Week 22, 2026 (25–31 May)

193 new CVEs this week, in line with the recent average. Severity skewed high: 26 critical and 97 high, 64% of the total. 9 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. linux was the most-affected vendor with 43.

193
New CVEs
26
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 193 published.

CVE-2026-46817Critical· 9.8CISA KEVPoC
3mo ago

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission)

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with netwo…

Hadaloracle · e-business_suiteEPSS 13%via NVD
CVE-2026-48710Medium· 6.5CISA KEVPoC
3mo ago

Starlette is a lightweight ASGI framework/toolkit

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `…

Midnightstarlette · starletteEPSS 36%via NVD
CVE-2026-4408Critical· 9.0PoC
3mo ago

A flaw was found in Samba

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution characte…

Abyssalredhat · openshift_container_platformEPSS 2.5%via NVD
CVE-2026-46372High· 8.5PoC
3mo ago

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern exposes /api/search/searx…

MidnightEPSS 0.87%via NVD
CVE-2026-46242High· 7.8PoC
3mo ago

In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under file->f_lock but then kept using @file inside t…

In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under file->f_lock but then kept using @file inside t…

Midnightlinux · linux_kernelEPSS 3.2%via NVD
CVE-2026-45700Critical· 9.8
3mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c, freerdp_bitmap_decompress_plan…

Midnightfreerdp · freerdpEPSS 4.4%via NVD
CVE-2026-45661Critical· 9.9
3mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitrary files to the filesystem during app…

MidnightEPSS 0.66%via NVD
CVE-2026-45633Critical· 9.9
3mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated an…

MidnightEPSS 0.92%via NVD
CVE-2026-45632Critical· 9.9
3mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, update, run, or delete schedules belongi…

MidnightEPSS 0.26%via NVD
CVE-2026-45631Critical· 10.0
3mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-secret-123456789") lets an unauthenticated attacker forge email verification JWTs, trigger…

MidnightEPSS 0.35%via NVD
CVE-2026-45629Critical· 9.9
3mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any organization member to execute arbitrary system commands on …

MidnightEPSS 0.76%via NVD
CVE-2026-44962Critical· 9.9
3mo ago

Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization

Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged u…

MidnightEPSS 0.69%via NVD

Most-affected vendors

By CVEs published in the period.