VulnSea

Daily digest

Monday 30 March 2026

20 new CVEs this day, in line with the recent average. Severity skewed high: 3 critical and 7 high, 50% of the total. 3 arrived with exploitation evidence or public exploit code already attached. nodejs was the most-affected vendor with 8.

20
New CVEs
3
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 20 published.

CVE-2026-21710High· 7.5PoC
6mo ago

A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `O…

A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `O…

▾ Midnightnodejs · node.jsEPSS 25%via NVD
CVE-2026-33641High· 7.8PoC
6mo ago

Glances Vulnerable to Command Injection via Dynamic Configuration Values

Glances Vulnerable to Command Injection via Dynamic Configuration Values

▾ Midnightglances · glancesEPSS 0.78%via OSV
CVE-2025-15379Critical· 10.0
6mo ago

A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function

A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependen…

▾ Midnightlfprojects · mlflowEPSS 2.4%via NVD
CVE-2025-15036Critical· 9.6
6mo ago

MLFlow path traversal vulnerability

MLFlow path traversal vulnerability

▾ Midnightmlflow · mlflowEPSS 0.58%via OSV
CVE-2026-34714Critical· 9.2
6mo ago

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

▾ MidnightEPSS 0.29%via NVD
CVE-2026-33030High· 8.8
6mo ago

nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys

nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys

▾ Twilight0xJacky · github.com/0xJacky/nginx-uiEPSS 0.38%via OSV
CVE-2026-21717Medium· 5.9PoC
6mo ago

A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable

A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, …

▾ Twilightnodejs · node.jsEPSS 0.27%via NVD
CVE-2026-5121High· 7.5
6mo ago

A flaw was found in libarchive

A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead t…

▾ Twilightlibarchive · libarchiveEPSS 1.4%via NVD
CVE-2026-27018High
6mo ago

Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)

Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)

▾ Twilightgotenberg · github.com/gotenberg/gotenberg/v8EPSS 1.6%via OSV
CVE-2026-3945High· 7.5
6mo ago

An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version 1.11.3 allows an unauthenticated remote attacker to cause a denial of service (DoS)

An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version 1.11.3 allows an unauthenticated remote attacker to cause a denial of service (DoS). The issue occurs because chunk s…

▾ TwilightEPSS 1.0%via NVD
CVE-2026-33533High
6mo ago

Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard

Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard

▾ Twilightglances · glancesEPSS 0.47%via OSV
CVE-2026-4266Medium· 6.7
6mo ago

An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user. No…

An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user. No…

▾ Sunlitwatchguard · firewareEPSS 0.39%via NVD

Most-affected vendors

By CVEs published in the period.