VulnSea

Weekly digest

Week 23, 2026 (1–7 Jun)

227 new CVEs this week, in line with the recent average. Of those, 13 critical and 84 high. 13 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. google was the most-affected vendor with 19.

227
New CVEs
13
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 227 published.

CVE-2026-8037Critical· 9.6CISA KEVPoC
3mo ago

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…

Hadalprogress · connection_manager_for_objectscaleEPSS 100%via NVD
CVE-2026-47117Critical· 9.8PoC
3mo ago

OpenMed vulnerable to remote code injection through privacy-filter model loading path

OpenMed vulnerable to remote code injection through privacy-filter model loading path

Abyssalopenmed · openmedEPSS 0.92%via OSV
CVE-2024-52011High· 8.3PoC
3mo ago

launch-editor allows users to open files with line numbers in editor from Node.js

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on W…

MidnightEPSS 0.51%via NVD
CVE-2026-41283Critical· 9.9
3mo ago

OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed

OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed

Midnightmistral · mistralEPSS 0.73%via OSV
CVE-2026-0091High· 7.8PoC
3mo ago

In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user

In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…

Midnightgoogle · androidEPSS 0.07%via NVD
CVE-2026-0009High· 7.8PoC
3mo ago

In multiple locations, there is a possible tapjacking due to a logic error in the code

In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Midnightgoogle · androidEPSS 0.09%via NVD
CVE-2026-25550Critical· 9.8
3mo ago

Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via BtSystem.Service.exe

Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via BtSystem.Service.exe. The service registers an unauthenticated singl…

MidnightSeagull Software, LLC. · BarTender 2010EPSS 0.88%via NVD
CVE-2026-47065Critical· 9.8
3mo ago

ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ),…

ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ),…

Midnightapache · minaEPSS 0.50%via NVD
CVE-2026-35075Critical· 9.8
3mo ago

An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.

An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.

Midnightmbs-solutions · universal_gateway_firmwareEPSS 0.47%via NVD
CVE-2026-41567High· 7.2PoC
3mo ago

Moby is an open source container framework

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, …

Midnightmoby · moby/v2/daemonEPSS 0.16%via NVD
CVE-2026-10290High· 7.3PoC
3mo ago

A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0

A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of the component GET Parameter Handler. Executing a manipulation of the argument t…

MidnightEPSS 0.32%via NVD
CVE-2026-46243High· 7.1PoC
3mo ago

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that …

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that …

Midnightlinux · linux_kernelEPSS 0.38%via NVD

Most-affected vendors

By CVEs published in the period.