VulnSea

Daily digest

Tuesday 31 March 2026

A heavy day: 141 new CVEs, well above the recent average of about 22. Severity skewed high: 25 critical and 49 high, 52% of the total. 13 arrived with exploitation evidence or public exploit code already attached. openclaw was the most-affected vendor with 20.

141
New CVEs
25
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 141 published.

CVE-2026-34156Critical· 9.9PoC
6mo ago

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a Node.js vm sandbox with …

▾ Abyssalnocobase · nocobaseEPSS 6.8%via NVD
CVE-2026-33579Critical· 9.9PoC
6mo ago

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can…

▾ Abyssalopenclaw · openclawEPSS 0.51%via NVD
CVE-2026-34243Critical· 9.8PoC
6mo ago

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title)

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_comment.body directly inside a shell com…

▾ Abyssalnjzjz · wenxianEPSS 2.8%via NVD
CVE-2026-34220Critical· 9.8PoC
6mo ago

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a SQL injection vulnerability when specially crafted objects are interpreted as raw SQL q…

▾ Abyssalmikro-orm · mikroormEPSS 0.47%via NVD
CVE-2026-34227High· 8.8PoC
6mo ago

Sliver is a command and control framework that uses a custom Wireguard netstack

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beaco…

▾ Midnightbishopfox · sliverEPSS 0.47%via NVD
CVE-2026-34040High· 8.4PoC
6mo ago

Moby: Moby: Authorization bypass vulnerability (CVE-2026-34040)

A flaw was found in Moby, an open-source container framework. This security vulnerability allows attackers to bypass authorization plugins (AuthZ), which are mechanisms designed to control access and permissions within the container enviro…

▾ MidnightRed Hat · Multicluster Global Hub 1.4.9EPSS 0.16%via CSAF
CVE-2026-4800High· 8.1PoC
6mo ago

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the s…

▾ Midnightlodash · lodashEPSS 2.6%via NVD
CVE-2026-34162Critical· 10.0
6mo ago

FastGPT is an AI Agent building platform

FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. This endpoint acts as a full HTTP proxy — it accepts a …

▾ Midnightfastgpt · fastgptEPSS 0.62%via NVD
CVE-2026-32917Critical· 9.8
6mo ago

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. The vulnerability exists because unsaniti…

▾ Midnightopenclaw · openclawEPSS 3.2%via NVD
CVE-2026-0596High· 7.8PoC
6mo ago

A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`

A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_uri` is embedded directly into a shell command executed via `bash -c` without proper sanitization. If the `model_uri` …

▾ Midnightlfprojects · mlflowEPSS 1.3%via NVD
CVE-2026-34453High· 7.5PoC
6mo ago

SiYuan is a personal knowledge management system

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish service exposes bookmarked blocks from password-protected documents to unauthenticated visitors. In publish/read-only mode, /api/bookmark/getBookmark f…

▾ Midnightb3log · siyuanEPSS 1.5%via NVD
CVE-2026-30314Critical· 9.8
6mo ago

Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective

Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command str…

▾ Midnightridvay · auto-approval_moduleEPSS 2.2%via NVD

Most-affected vendors

By CVEs published in the period.