Daily digest
Friday 3 April 2026
A heavy day: 109 new CVEs, well above the recent average of about 41. Severity skewed high: 16 critical and 47 high, 58% of the total. 12 arrived with exploitation evidence or public exploit code already attached. linux was the most-affected vendor with 48.
New this day, ranked by depth score
The 12 that matter most of the 109 published.
CVE-2026-0545Critical· 9.8PoCIn mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled
In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job e…
CVE-2026-31402Critical· 9.8PoCIn the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 112-byte inline buffer (rp_ibuf[NFSD4_REPLAY_ISIZE]) to store encoded operat…
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 112-byte inline buffer (rp_ibuf[NFSD4_REPLAY_ISIZE]) to store encoded operat…
CVE-2026-28766Critical· 9.3PoCA specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.
A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.
CVE-2026-25197Critical· 9.1PoCA specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.
A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.
CVE-2026-33752High· 8.6PoCcurl_cffi: Redirect-based SSRF leads to internal network access in curl_cffi (with TLS impersonation bypass)
curl_cffi: Redirect-based SSRF leads to internal network access in curl_cffi (with TLS impersonation bypass)
CVE-2025-10681High· 8.6PoCStorage credentials are hardcoded in the mobile app and device firmware
Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end user permissions and do not expire within a reasonable amount of time. This vulnerability may grant unauthorized acces…
CVE-2026-4350High· 8.1PoCThe Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1
The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter…
CVE-2026-32186Critical· 10.0Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-35029HighPoCLiteLLM: Privilege escalation via unrestricted proxy configuration endpoint
LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint
CVE-2026-23450Critical· 9.8net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock()
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller reported a panic in smc_tcp_syn_recv_sock() [1]. smc_tcp_syn_recv_sock() is called in the T…
CVE-2018-25237Critical· 9.8Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication is enabled that allows remote attackers to crash the device or execute arbitrary code by…
Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication is enabled that allows remote attackers to crash the device or execute arbitrary code by…
CVE-2018-25236Critical· 9.8Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administ…
Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administ…
Most-affected vendors
By CVEs published in the period.