VulnSea

Daily digest

Wednesday 18 March 2026

A busier-than-usual day with 28 new CVEs (recent average about 18). Severity skewed high: 2 critical and 15 high, 61% of the total. One arrived with exploitation evidence or public exploit code already attached. Linux was the most-affected vendor with 8.

28
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 28 published.

CVE-2026-27459Critical· 9.8⚖ disputed
6mo ago

pyOpenSSL is a Python wrapper around the OpenSSL library

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL wou…

▾ Midnightpyopenssl · pyopensslEPSS 0.88%via NVD
CVE-2026-31938Critical· 9.6
6mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the `output` function allows attackers to inject arbitrary HTML (such as scripts) into the browser context the created P…

▾ Midnightparall · jspdfEPSS 0.40%via NVD
CVE-2026-30922High· 7.5PoC
6mo ago

pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)

An unbounded recursion flaw has been discovered in the pypi pyasn1 library. This uncontrolled recursion occurs when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing nested SEQUENCE (0x3…

▾ MidnightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.93%via CSAF
CVE-2026-33001High· 8.8
6mo ago

Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted on…

Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted on…

▾ Twilightjenkins · jenkinsEPSS 1.2%via NVD
CVE-2026-31898High· 8.1
6mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnotation` method allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to p…

▾ Twilightparall · jspdfEPSS 0.62%via NVD
CVE-2026-26740High· 8.2
6mo ago

Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without validating its allocated size.

Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without validating its allocated size.

▾ Twilightgiflib_project · giflibEPSS 1.0%via NVD
CVE-2026-2603High· 8.1
6mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attac…

▾ Twilightredhat · build_of_keycloakEPSS 0.72%via NVD
CVE-2026-23270High· 7.8
6mo ago

net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks

In the Linux kernel, the following vulnerability has been resolved: net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks As Paolo said earlier [1]: "Since the blamed commit below, classify can return TC_ACT_…

▾ TwilightLinux · LinuxEPSS 0.13%via CVEORG
CVE-2026-23245High· 7.8
6mo ago

net/sched: act_gate: snapshot parameters with RCU on replace

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_gate: snapshot parameters with RCU on replace The gate action can be replaced while the hrtimer callback or dump path is walking the schedule list. Con…

▾ TwilightLinux · LinuxEPSS 0.13%via CVEORG
CVE-2026-23243High· 7.8
6mo ago

RDMA/umad: Reject negative data_len in ib_umad_write

In the Linux kernel, the following vulnerability has been resolved: RDMA/umad: Reject negative data_len in ib_umad_write ib_umad_write computes data_len from user-controlled count and the MAD header sizes. With a mismatched user MAD he…

▾ TwilightLinux · LinuxEPSS 0.13%via CVEORG
CVE-2026-33155High
6mo ago

DeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORT

DeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORT

▾ Twilightdeepdiff · deepdiffEPSS 0.52%via OSV
CVE-2026-33139High
6mo ago

PySpector has a Plugin Sandbox Bypass leads to Arbitrary Code Execution

PySpector has a Plugin Sandbox Bypass leads to Arbitrary Code Execution

▾ Twilightpyspector · pyspectorEPSS 0.18%via OSV

Most-affected vendors

By CVEs published in the period.