VulnSea

Daily digest

Friday 6 March 2026

10 new CVEs this day, in line with the recent average. Severity skewed high: 2 critical and 6 high, 80% of the total.

10
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 10 that matter most of the 10 published.

CVE-2026-29063Critical· 9.8
6mo ago

Immutable.js provides many Persistent Immutable data structures

Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. …

▾ Midnightimmutable-js · immutableEPSS 1.2%via NVD
CVE-2026-28802Critical· 9.8⚖ disputed
6mo ago

Authlib is a Python library which builds OAuth and OpenID Connect servers

Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature…

▾ Midnightauthlib · authlibEPSS 0.55%via NVD
CVE-2026-26017High· 7.7
6mo ago

CoreDNS is a DNS server that chains plugins

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated …

▾ Twilightcoredns.io · corednsEPSS 0.46%via NVD
CVE-2026-29074High· 7.5
6mo ago

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 2.1.0 to before version 2.8.1, from version 3.0.0 to before version 3.3.3, and before version 4.0.1, SVGO accepts XML…

▾ Twilightsvgo · svgoEPSS 0.93%via NVD
CVE-2026-27137High· 7.5
6mo ago

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the l…

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the l…

▾ Twilightgolang · goEPSS 0.66%via NVD
CVE-2026-26018High· 7.5
6mo ago

CoreDNS is a DNS server that chains plugins

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin that allows an attacker to crash the DNS server by sending specially crafted DNS queries. T…

▾ Twilightcoredns.io · corednsEPSS 0.76%via NVD
CVE-2026-25679High· 7.5
6mo ago

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

▾ Twilightgolang · goEPSS 0.80%via NVD
CVE-2025-70363High· 7.5
6mo ago

Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive data via enumerating object IDs.

Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive data via enumerating object IDs.

▾ Twilightibexa · ez_platformEPSS 0.24%via NVD
CVE-2026-29049Medium· 4.3
6mo ago

melange allows users to build apk packages using declarative pipelines

melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cac…

▾ Sunlitchainguard · melangeEPSS 0.39%via NVD
CVE-2026-1468None
6mo ago

QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints

QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. An attacker can craft special website, which when visited by the victim, will automatically send a POST request with victim's privileges. This software does …

▾ SunlitEPSS 0.22%via NVD

Most-affected vendors

By CVEs published in the period.