Daily digest
Sunday 29 March 2026
A quiet day: only 6 new CVEs against a recent average of about 20. Severity skewed high: 1 critical and 5 high, 100% of the total. 2 arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 6 that matter most of the 6 published.
CVE-2026-0558Critical· 9.8PoCA vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through t…
A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not enforce authentication, unlike other f…
CVE-2026-0560High· 7.5PoCA Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/exp…
A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. The `_download_image_to_temp()` function in `backend/routers/files.py` fails …
CVE-2026-4946High· 8.8Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary command execution when an analyst interacts with the UI
Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary command execution when an analyst interacts with the UI. Specifically, the @execute annotati…
GHSA-46wh-3698-f2cxHighTraefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)
Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)
CVE-2026-56341High· 7.5AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
CVE-2026-32287High· 7.5XPath: Boolean expression infinite loop leads to denial of service via CPU exhaustion
XPath: Boolean expression infinite loop leads to denial of service via CPU exhaustion
Most-affected vendors
By CVEs published in the period.