Date: June 19, 2026 Lookback window: 1 day CVEs evaluated: 1742 CVEs in window: 69 (69 new)
Sources: NVD: 40 | GitHub: 80 | CISA KEV: 1623
| Classification | Count | Reported |
|---|---|---|
| Vendor Products | 45 | summary only |
| Open-Source Libraries | 22 | 22 (see below) |
| Web App / CMS Plugins | 2 | summary only |
Worth tracking but may not need a dedicated extension yet.
| CVE | CVE-2026-48814 |
| Published | June 19, 2026 |
| Severity | CRITICAL (9.1) |
| Classification | Open-Source Libraries |
| Source | GitHub Advisory |
| Affected | npm / network-ai |
| Actionability | 4.4/10 — Monitor |
| Impact | ░░░░░ 0/3 |
| Scannable | ███░░ 2/3 |
| Remediation | ███░░ 2/3 |
Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests
Why: dependency scanning can detect this; credential rotation may be needed
https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-r78r-rwrf-rjwp
| CVE | GHSA-GHSA-r253-r9jw-qg44 |
| Published | June 18, 2026 |
| Severity | CRITICAL (10) |
| Classification | Open-Source Libraries |
| Source | GitHub Advisory |
| Categories | rce |
| Affected | pip / crawl4ai |
| Actionability | 4.4/10 — Monitor |
| Impact | ███░░ 2/3 |
| Scannable | ███░░ 2/3 |
| Remediation | ░░░░░ 0/3 |
Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args
Why: dependency scanning can detect this; remote code execution
https://github.com/unclecode/crawl4ai/security/advisories/GHSA-r253-r9jw-qg44
| CVE | GHSA-GHSA-2jq4-q6vv-4cp3 |
| Published | June 18, 2026 |
| Severity | CRITICAL (9.6) |
| Classification | Open-Source Libraries |
| Source | GitHub Advisory |
| Categories | rce |
| Affected | pip / crawl4ai |
| Actionability | 4.4/10 — Monitor |
| Impact | ███░░ 2/3 |
| Scannable | ███░░ 2/3 |
| Remediation | ░░░░░ 0/3 |
Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE
Why: dependency scanning can detect this; remote code execution
https://github.com/unclecode/crawl4ai/security/advisories/GHSA-2jq4-q6vv-4cp3
| CVE | GHSA-GHSA-gfj5-979r-92pw |
| Published | June 18, 2026 |
| Severity | CRITICAL (9) |
| Classification | Open-Source Libraries |
| Source | GitHub Advisory |
| Categories | auth-bypass |
| Affected | npm / @acastellon/auth |
| Actionability | 4.4/10 — Monitor |
| Impact | ░░░░░ 0/3 |
| Scannable | ███░░ 2/3 |
| Remediation | ███░░ 2/3 |
@acastellon/auth: Authentication bypass via spoofable headers in validateToken()
Why: dependency scanning can detect this; credential rotation may be needed
https://github.com/antonio-castellon/module-auth/security/advisories/GHSA-gfj5-979r-92pw
| CVE | GHSA-GHSA-hxpf-9xvq-wph8 |
| Published | June 18, 2026 |
| Severity | CRITICAL (9.6) |
| Classification | Open-Source Libraries |
| Source | GitHub Advisory |
| Affected | pip / netlicensing-mcp |
| Actionability | 5.5/10 — Monitor |
| Impact | ██░░░ 1/3 |
| Scannable | ███░░ 2/3 |
| Remediation | ███░░ 2/3 |
netlicensing-mcp: REST Path Traversal Bypasses Token Redaction
Why: dependency scanning can detect this; credential rotation may be needed
https://github.com/Labs64/NetLicensing-MCP/security/advisories/GHSA-hxpf-9xvq-wph8
These are in categories you care about (supply-chain, infrastructure, open-source libraries, or actively exploited) but don't need special tooling.
-
DotVVM (NEW) — Open-Source Libraries — CRITICAL (9) — June 19, 2026 DotVVM: Missing authorization in AuthorizeActionFilter
-
Tilt (NEW) — Open-Source Libraries — CRITICAL (9) — June 19, 2026 Tilt: Missing authentication on the network-exposed Tilt HUD server
-
Network-AI (NEW) — Open-Source Libraries — CRITICAL (9.9) — June 19, 2026 Network-AI: Improper Neutralization of Special Elements used in an OS Command
-
npm/gemini-mcp-tool (NEW) — Open-Source Libraries — CRITICAL (9.8) — June 18, 2026 gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)
-
OpenTofu (NEW) — Open-Source Libraries — HIGH (7.5) — June 19, 2026 OpenTofu: Possible arbitrary file read during certain git operations via a maliciously crafted URL
-
Agentic-Flow (NEW) — Open-Source Libraries — HIGH (8.8) — June 19, 2026 Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync
-
ouroboros-ai (NEW) — Open-Source Libraries — HIGH (7.5) — June 19, 2026 ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys
-
nuget/DotVVM (NEW) — Open-Source Libraries — HIGH (7.5) — June 19, 2026 ReDoS in DotVVM routing
-
agent-coderag (NEW) — Open-Source Libraries — HIGH (8.6) — June 19, 2026 agent-coderag: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Execution
-
parse-server (NEW) — Open-Source Libraries — HIGH (7.5) — June 19, 2026 parse-server: Denial of service via exponential-time processing of deeply nested query operators
-
pip/bedrock-agentcore (NEW) — Open-Source Libraries — HIGH (7.3) — June 19, 2026 Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
-
maven/com.cedarpolicy:cedar-java (NEW) — Open-Source Libraries — HIGH (8.8) — June 19, 2026 CedarJava has policy injection vulnerability
-
maven/com.cedarpolicy:cedar-java (NEW) — Open-Source Libraries — HIGH (8.8) — June 19, 2026 CedarJava has type confusion vulnerability
-
npm/undici (NEW) — Open-Source Libraries — HIGH (7.5) — June 19, 2026 undici WebSocket client vulnerable to denial of service via fragment count bypass
-
npm/undici (NEW) — Open-Source Libraries — HIGH (7.5) — June 19, 2026 undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
-
Tilt (NEW) — Open-Source Libraries — HIGH (7.5) — June 19, 2026 Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream
-
Tilt (NEW) — Open-Source Libraries — HIGH (7.5) — June 19, 2026 Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server
47 additional CVEs in vendor products and web app plugins — standard patching, no action needed.
| Severity | Count |
|---|---|
| Critical | 20 |
| High | 27 |
| Classification | Count |
|---|---|
| Vendor Products | 45 |
| Web App / CMS Plugins | 2 |
Each CVE is classified (supply-chain, infrastructure, open-source library, vendor product, web app) and scored on three dimensions (0-3 each):
- Impact: How many systems/users are affected?
- Scannable: Can exposure be detected programmatically?
- Remediation: Are there steps beyond just updating?
Total score (0-10) determines the recommendation:
- 7+ = Extension candidate — build a swamp scanner
- 4-6 = Monitor — track, but standard patching may suffice
- <4 = Patch only — update and move on
Vendor product bugs and web app plugin vulns are summarised unless actively exploited (CISA KEV).
Sources: NVD, GitHub Advisory DB, CISA Known Exploited Vulnerabilities