VulnSea

Daily digest

Thursday 12 March 2026

18 new CVEs this day, in line with the recent average. Severity skewed high: 1 critical and 8 high, 50% of the total. One arrived with exploitation evidence or public exploit code already attached. nodejs was the most-affected vendor with 3.

18
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 18 published.

CVE-2026-32247High· 8.1PoC
6mo ago

Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters

Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters

▾ Midnightgraphiti-core · graphiti-coreEPSS 0.48%via OSV
CVE-2026-28384Critical· 9.9
6mo ago

An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints

An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This iss…

▾ Midnightcanonical · lxdEPSS 0.86%via NVD
CVE-2026-3989High· 7.8
6mo ago

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization

▾ Twilightsglang · sglangEPSS 0.43%via OSV
CVE-2026-32274High· 7.5
6mo ago

Black: Arbitrary file writes from unsanitized user input in cache file name

Black: Arbitrary file writes from unsanitized user input in cache file name

▾ Twilightblack · blackEPSS 0.72%via OSV
CVE-2026-32141High· 7.5
6mo ago

flatted is a circular JSON parser

flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indi…

▾ Twilightwebreflection · flattedEPSS 0.99%via NVD
CVE-2026-28356High· 7.5
6mo ago

multipart is a fast multipart/form-data parser for python

multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header() function in multipart.py uses a regular expression with an ambiguous alternation, which can cause exponential back…

▾ Twilightmultipart · multipartEPSS 1.0%via NVD
CVE-2026-2229High· 7.5
6mo ago

ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension

ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it automa…

▾ Twilightnodejs · undiciEPSS 0.87%via NVD
CVE-2026-1528High· 7.5
6mo ago

ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length

ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the proces…

▾ Twilightnodejs · undiciEPSS 0.49%via NVD
CVE-2026-1526High· 7.5
6mo ago

The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression

The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompr…

▾ Twilightnodejs · undiciEPSS 1.1%via NVD
CVE-2026-32112Medium· 6.8
6mo ago

ha-mcp has XSS via Unescaped HTML in OAuth Consent Form

ha-mcp has XSS via Unescaped HTML in OAuth Consent Form

▾ Sunlitha-mcp · ha-mcpEPSS 0.24%via OSV
CVE-2026-2514Medium· 6.1
6mo ago

In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed by Flowmon ADS and viewed by an authen…

In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed by Flowmon ADS and viewed by an authen…

▾ Sunlitprogress · flowmon_anomaly_detection_systemEPSS 0.18%via NVD
CVE-2026-2513Medium· 6.1
6mo ago

A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web …

A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web …

▾ Sunlitprogress · flowmon_anomaly_detection_systemEPSS 0.16%via NVD

Most-affected vendors

By CVEs published in the period.