VulnSea

Weekly digest

Week 25, 2026 (15–21 Jun)

A heavy week: 766 new CVEs, well above the recent average of about 237. Severity skewed high: 88 critical and 327 high, 54% of the total. 32 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. openclaw was the most-affected vendor with 54.

766
New CVEs
88
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 766 published.

CVE-2026-12569Critical· 9.8CISA KEV
3mo ago

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS…

Hadalptc · flexplmEPSS 41%via NVD
CVE-2026-48939Critical· 9.8CISA KEVPoC
3mo ago

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

Hadaljoomlic · icagendaEPSS 20%via NVD
CVE-2026-55255Critical· 9.9CISA KEVPoC
3mo ago

Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow

Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow

Hadallangflow · langflowEPSS 0.89%via GHSA
CVE-2026-0755Critical· 9.80day
3mo ago

gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)

gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)

Hadalgemini-mcp-tool · gemini-mcp-toolEPSS 3.5%via GHSA
CVE-2026-7273High· 8.8CISA KEVPoC
3mo ago

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via …

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via …

Abyssalzyxel · gs1900-8_firmwareEPSS 0.32%via NVD
CVE-2026-56265Critical· 9.8PoC
3mo ago

Crawl4AI: authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server

Crawl4AI: authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server

Abyssalcrawl4ai · crawl4aiEPSS 2.6%via GHSA
CVE-2026-47103Critical· 9.8PoC
3mo ago

python-statemachine SCXML <data expr> Eval Injection

python-statemachine SCXML <data expr> Eval Injection

Abyssalpython-statemachine · python-statemachineEPSS 1.4%via GHSA
CVE-2026-53753Critical· 9.8PoC
3mo ago

Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API

Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API

Abyssalcrawl4ai · crawl4aiEPSS 2.9%via GHSA
CVE-2026-49468Critical· 9.8PoC
3mo ago

LiteLLM: Authentication Bypass via Host Header Injection

LiteLLM: Authentication Bypass via Host Header Injection

Abyssallitellm · litellmEPSS 0.82%via OSV
CVE-2026-12295Critical· 9.6PoC
3mo ago

Sandbox escape in the DOM: Navigation component

Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Abyssalmozilla · firefoxEPSS 0.39%via NVD
CVE-2026-55450Critical· 9.3PoC
3mo ago

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

Abyssallangflow · langflowEPSS 1.2%via GHSA
CVE-2026-54157Critical· 9.0PoC
3mo ago

LobeHub: Unauthenticated SSRF in `/webapi/proxy`

LobeHub: Unauthenticated SSRF in `/webapi/proxy`

Abyssallobehub · @lobehub/lobehubEPSS 1.8%via GHSA

Most-affected vendors

By CVEs published in the period.