VulnSea

Daily digest

Friday 20 March 2026

A busier-than-usual day with 21 new CVEs (recent average about 14). Severity skewed high: 5 critical and 12 high, 81% of the total. 3 arrived with exploitation evidence or public exploit code already attached. CISA added 3 CVEs to the Known Exploited Vulnerabilities catalog. Linux was the most-affected vendor with 6.

21
New CVEs
5
Critical
3
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 21 published.

CVE-2026-33186Critical· 9.1PoC
6mo ago

gRPC-Go is the Go language implementation of gRPC

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logi…

▾ Abyssalgrpc · grpcEPSS 1.6%via NVD
CVE-2026-22172Critical· 9.9
6mo ago

OpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth Connections

OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. …

▾ MidnightOpenClaw · OpenClawEPSS 0.56%via CVEORG
CVE-2026-33231High· 7.5PoC
6mo ago

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthentic…

▾ Midnightnltk · nltkEPSS 1.5%via NVD
CVE-2026-33228Critical· 9.8
6mo ago

flatted is a circular JSON parser

flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the int…

▾ MidnightEPSS 0.99%via NVD
CVE-2025-15608Critical· 9.8
6mo ago

This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected servi…

This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected servi…

▾ Midnighttp-link · archer_ax53_firmwareEPSS 0.64%via NVD
CVE-2026-33154High· 7.5PoC
6mo ago

dynaconf: jinja2: Dynaconf: Arbitrary code execution via Server-Side Template Injection (CVE-2026-33154)

A flaw was found in dynaconf, a Python configuration management tool. This Server-Side Template Injection (SSTI) vulnerability occurs due to unsafe template evaluation in the @Jinja resolver when the jinja2 package is installed. A remote a…

▾ MidnightRed Hat · Red Hat Ansible Automation Platform 2EPSS 0.57%via CSAF
CVE-2026-33210Critical· 9.1
6mo ago

Ruby JSON is a JSON implementation for Ruby

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_d…

▾ Midnightruby-lang · jsonEPSS 1.0%via NVD
CVE-2026-33243High· 8.2
6mo ago

barebox is a bootloader

barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature verification vulnerability to trick the bootloader into booti…

▾ Twilightpengutronix · bareboxEPSS 0.12%via NVD
CVE-2026-33236High· 8.1
6mo ago

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does not validate the…

▾ Twilightnltk · nltkEPSS 0.71%via NVD
CVE-2026-32711High· 7.8
6mo ago

pydicom has a path traversal in FileSet/DICOMDIR ReferencedFileID allows file access outside the File-set root

pydicom has a path traversal in FileSet/DICOMDIR ReferencedFileID allows file access outside the File-set root

▾ Twilightpydicom · pydicomEPSS 0.22%via OSV
CVE-2026-23278High· 7.8
6mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: always walk all pending catchall elements During transaction processing we might have more than one catchall element: 1 live catchall element and…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: always walk all pending catchall elements During transaction processing we might have more than one catchall element: 1 live catchall element and…

▾ Twilightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-23274High· 7.8
6mo ago

netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels

In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels IDLETIMER revision 0 rules reuse existing timers by label and always call mod_timer() on timer->timer.…

▾ TwilightLinux · LinuxEPSS 0.18%via CVEORG

Most-affected vendors

By CVEs published in the period.