VulnSea

Daily digest

Tuesday 24 March 2026

A busier-than-usual day with 19 new CVEs (recent average about 15). Severity skewed high: 2 critical and 8 high, 53% of the total. 3 arrived with exploitation evidence or public exploit code already attached. zabbix was the most-affected vendor with 5.

19
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 19 published.

CVE-2026-33634CriticalCISA KEVPoC
6mo ago

Trivy ecosystem supply chain was briefly compromised

Trivy ecosystem supply chain was briefly compromised

▾ Hadalaquasecurity · github.com/aquasecurity/trivyEPSS 1.7%via OSV
CVE-2026-23921High· 8.8PoC
6mo ago

A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter

A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned dire…

▾ Midnightzabbix · zabbixEPSS 3.5%via NVD
CVE-2026-22739High· 8.6PoC
6mo ago

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configu…

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configu…

▾ Midnightvmware · spring_cloud_configEPSS 1.2%via NVD
CVE-2026-33211Critical· 9.6
6mo ago

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path tr…

▾ Midnightlinuxfoundation · tekton_pipelinesEPSS 0.70%via NVD
CVE-2026-23920High· 8.8
6mo ago

Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode

Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass…

▾ Twilightzabbix · zabbixEPSS 0.30%via NVD
CVE-2026-4775High· 7.8
6mo ago

A flaw was found in the libtiff library

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds …

▾ TwilightEPSS 0.38%via NVD
CVE-2026-24159High· 7.8
6mo ago

NVIDIA NeMo Framework contains a vulnerability leading to Remote Code Execution

NVIDIA NeMo Framework contains a vulnerability leading to Remote Code Execution

▾ Twilightnemo-toolkit · nemo-toolkitEPSS 0.64%via OSV
CVE-2026-24157High· 7.8
6mo ago

NVIDIA NeMo Framework contains an RCE vulnerability in checkpoint loading

NVIDIA NeMo Framework contains an RCE vulnerability in checkpoint loading

▾ Twilightnemo-toolkit · nemo-toolkitEPSS 0.65%via OSV
CVE-2026-1995High· 7.8
6mo ago

In versions before 7.0.0.64, IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory

In versions before 7.0.0.64, IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory. The UTF16-LE encoded contents of these files are used as argume…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-5389High
6mo ago

JustHTML is vulnerable to XSS via code fence breakout in <pre> content

JustHTML is vulnerable to XSS via code fence breakout in <pre> content

▾ Twilightjusthtml · justhtmlEPSS 0.26%via OSV
CVE-2026-33246Medium· 6.4
6mo ago

NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers

NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers

▾ Sunlitnats-io · github.com/nats-io/nats-server/v2EPSS 0.24%via OSV
CVE-2026-23919Medium· 6.0
6mo ago

For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks)

For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data…

▾ Sunlitzabbix · zabbixEPSS 0.24%via NVD

Most-affected vendors

By CVEs published in the period.