VulnSea

Daily digest

Saturday 28 March 2026

A quiet day: only 3 new CVEs against a recent average of about 22. Severity skewed high: 2 critical, 67% of the total.

3
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 3 that matter most of the 3 published.

CVE-2026-3256Critical· 9.8
6mo ago

HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids. HTTP::Session defaults to using HTTP::Session::ID::SHA1 to generate session ids using a SHA-1 hash seeded with the built-in rand function, t…

HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids. HTTP::Session defaults to using HTTP::Session::ID::SHA1 to generate session ids using a SHA-1 hash seeded with the built-in rand function, t…

▾ MidnightEPSS 0.71%via NVD
CVE-2025-9497Critical· 9.8
6mo ago

Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0.

Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0.

▾ Midnightmicrochip · timeprovider_4100_firmwareEPSS 0.32%via NVD
CVE-2026-23399Medium· 5.5
6mo ago

In the Linux kernel, the following vulnerability has been resolved: nf_tables: nft_dynset: fix possible stateful expression memleak in error path If cloning the second stateful expression in the element via GFP_ATOMIC fails, then the f…

In the Linux kernel, the following vulnerability has been resolved: nf_tables: nft_dynset: fix possible stateful expression memleak in error path If cloning the second stateful expression in the element via GFP_ATOMIC fails, then the f…

▾ Sunlitlinux · linux_kernelEPSS 0.12%via NVD

Most-affected vendors

By CVEs published in the period.