VulnSea

Daily digest

Monday 23 March 2026

15 new CVEs this day, in line with the recent average. Severity skewed high: 3 critical and 7 high, 67% of the total. 3 arrived with exploitation evidence or public exploit code already attached. kjur was the most-affected vendor with 5.

15
New CVEs
3
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 15 published.

CVE-2026-31848Critical· 9.8
6mo ago

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix. Because the encoding is reversible and lacks integr…

▾ Midnightnexxtsolutions · nebula300plus_firmwareEPSS 0.46%via NVD
CVE-2026-4602High· 7.5PoC
6mo ago

Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js

Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and brea…

▾ Midnightkjur · jsrsasignEPSS 0.88%via NVD
CVE-2026-4600High· 7.4PoC
6mo ago

Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/ds…

Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/ds…

▾ Midnightkjur · jsrsasignEPSS 0.32%via NVD
CVE-2026-4598High· 7.5PoC
6mo ago

Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang th…

Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang th…

▾ Midnightkjur · jsrsasignEPSS 0.96%via NVD
CVE-2026-4404Critical· 9.4
6mo ago

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

▾ Midnightlinuxfoundation · harborEPSS 0.57%via NVD
CVE-2026-4599Critical· 9.1
6mo ago

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker …

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker …

▾ Midnightkjur · jsrsasignEPSS 0.78%via NVD
CVE-2026-31847High· 8.8
6mo ago

Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service

Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service. By sending a crafted POST request with parameters such as telnetMa…

▾ Twilightnexxtsolutions · nebula300plus_firmwareEPSS 0.68%via NVD
CVE-2026-4601High· 8.7
6mo ago

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s…

▾ Twilightkjur · jsrsasignEPSS 0.47%via NVD
CVE-2026-32845High· 8.4
6mo ago

cgltf version 1.15 and prior contain an integer overflow vulnerability in the cgltf_validate() function when validating sparse accessors that allows attackers to trigger out-of-bounds reads by supplying crafted glTF/GLB input files with …

cgltf version 1.15 and prior contain an integer overflow vulnerability in the cgltf_validate() function when validating sparse accessors that allows attackers to trigger out-of-bounds reads by supplying crafted glTF/GLB input files with …

▾ TwilightEPSS 0.20%via NVD
CVE-2026-33046High
6mo ago

Indico discloses local files resulting in Remote Code Execution through LaTeX injection

Indico discloses local files resulting in Remote Code Execution through LaTeX injection

▾ Twilightindico · indicoEPSS 1.0%via OSV
CVE-2026-31846Medium· 6.5
6mo ago

Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows an adjacent unauthenticated attacker to retrieve sensitive device information, including the administrator pass…

Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows an adjacent unauthenticated attacker to retrieve sensitive device information, including the administrator pass…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-4647Medium· 6.1
6mo ago

A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables

A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type valu…

▾ Sunlitgnu · binutilsEPSS 0.17%via NVD

Most-affected vendors

By CVEs published in the period.