VulnSea

Daily digest

Monday 16 March 2026

A heavy day: 32 new CVEs, well above the recent average of about 14. Severity skewed high: 2 critical and 22 high, 75% of the total. 6 arrived with exploitation evidence or public exploit code already attached. glances was the most-affected vendor with 7.

32
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 32 published.

CVE-2026-3085High· 8.80day
6mo ago

GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability

GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required…

▾ Abyssalgstreamer · gstreamerEPSS 1.2%via NVD
CVE-2026-3083High· 8.80day
6mo ago

GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability

GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exp…

▾ Abyssalgstreamer · gstreamerEPSS 1.1%via NVD
CVE-2026-3082High· 7.80day
6mo ago

GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability

GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required …

▾ Abyssalgstreamer · gstreamerEPSS 0.38%via NVD
CVE-2026-2923High· 7.80day
6mo ago

GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability

GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to ex…

▾ Abyssalgstreamer · gstreamerEPSS 0.34%via NVD
CVE-2026-2922High· 7.80day
6mo ago

GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability

GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required t…

▾ Abyssalgstreamer · gstreamerEPSS 0.34%via NVD
CVE-2026-2921High· 7.80day
6mo ago

GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability

GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploi…

▾ Abyssalgstreamer · gstreamerEPSS 0.35%via NVD
CVE-2026-2920High· 7.80day
6mo ago

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required …

▾ Abyssalgstreamer · gstreamerEPSS 0.37%via NVD
CVE-2026-27962Critical· 9.1PoC
6mo ago

Authlib is a Python library which builds OAuth and OpenID Connect servers

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that…

▾ Abyssalauthlib · authlibEPSS 0.52%via NVD
CVE-2025-50881High· 8.8PoC
6mo ago

The `flow/admin/moniteur.php` script in Use It Flow administration website before 10.0.0 is vulnerable to Remote Code Execution

The `flow/admin/moniteur.php` script in Use It Flow administration website before 10.0.0 is vulnerable to Remote Code Execution. When handling GET requests, the script takes user-supplied input from the `action` URL parameter, performs i…

▾ MidnightEPSS 0.61%via NVD
CVE-2026-32640Critical· 9.8
6mo ago

SimpleEval is a library for adding evaluatable expressions into python projects

SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modules) can leak dangerous modules through to direct access inside the sandbox. If the objects you've passed in as names…

▾ Midnightdanthedeckie · simpleevalEPSS 0.78%via NVD
CVE-2026-32596HighPoC
6mo ago

Glances exposes the REST API without authentication

Glances exposes the REST API without authentication

▾ Midnightglances · glancesEPSS 1.7%via OSV
CVE-2026-28498High· 7.5PoC
6mo ago

Authlib is a Python library which builds OAuth and OpenID Connect servers

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. S…

▾ Midnightauthlib · authlibEPSS 0.26%via NVD

Most-affected vendors

By CVEs published in the period.