VulnSea

Daily digest

Thursday 19 March 2026

17 new CVEs this day, in line with the recent average. Of those, 1 critical and 6 high. 5 arrived with exploitation evidence or public exploit code already attached. bmc was the most-affected vendor with 4.

17
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 17 published.

CVE-2025-71257High· 7.3PoC
6mo ago

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets. Unauthenticated remote attackers can…

▾ Midnightbmc · footprintsEPSS 45%via NVD
CVE-2026-33310High· 8.8PoC
6mo ago

Intake has a Command Injection via shell() Expansion in Parameter Defaults

Intake has a Command Injection via shell() Expansion in Parameter Defaults

▾ Midnightintake · intakeEPSS 0.49%via OSV
CVE-2025-71260High· 8.8
6mo ago

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can…

▾ Twilightbmc · footprintsEPSS 34%via NVD
CVE-2026-33322Critical
6mo ago

MinIO has JWT Algorithm Confusion in OIDC Authentication

MinIO has JWT Algorithm Confusion in OIDC Authentication

▾ Midnightminio · github.com/minio/minioEPSS 0.61%via OSV
CVE-2026-33320Medium· 6.2PoC
6mo ago

Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service

Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service

▾ Twilighttomwright · github.com/tomwright/dasel/v3EPSS 0.17%via OSV
CVE-2025-15031High· 8.1
6mo ago

Arbitrary file write via tar traversal in mlflow

Arbitrary file write via tar traversal in mlflow

▾ Twilightmlflow · mlflowEPSS 0.85%via OSV
CVE-2026-4424High· 7.5
6mo ago

A flaw was found in libarchive

A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote atta…

▾ Twilightlibarchive · libarchiveEPSS 1.1%via NVD
CVE-2026-27953High· 7.1
6mo ago

ormar Pydantic Validation Bypass via __pk_only__ and __excluded__ Kwargs Injection in Model Constructor

ormar Pydantic Validation Bypass via __pk_only__ and __excluded__ Kwargs Injection in Model Constructor

▾ Twilightormar · ormarEPSS 0.91%via OSV
CVE-2025-71258Medium· 4.3PoC
6mo ago

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound re…

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound re…

▾ Twilightbmc · footprintsEPSS 17%via NVD
CVE-2025-71259Medium· 4.3PoC
6mo ago

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from th…

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from th…

▾ Twilightbmc · footprintsEPSS 13%via NVD
CVE-2026-4426Medium· 6.5
6mo ago

A flaw was found in libarchive

A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit …

▾ Sunlitlibarchive · libarchiveEPSS 0.56%via NVD
CVE-2026-32889Medium· 6.5
6mo ago

Denial of service via non-terminating SYLT frame parsing loop in tinytag

Denial of service via non-terminating SYLT frame parsing loop in tinytag

▾ Sunlittinytag · tinytagEPSS 0.49%via OSV

Most-affected vendors

By CVEs published in the period.