VulnSea

Daily digest

Friday 3 April 2026

A heavy day: 109 new CVEs, well above the recent average of about 41. Severity skewed high: 16 critical and 47 high, 58% of the total. 12 arrived with exploitation evidence or public exploit code already attached. linux was the most-affected vendor with 48.

109
New CVEs
16
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 109 published.

CVE-2026-0545Critical· 9.8PoC
5mo ago

In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled

In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job e…

▾ Abyssallfprojects · mlflowEPSS 4.4%via NVD
CVE-2026-31402Critical· 9.8PoC
5mo ago

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 112-byte inline buffer (rp_ibuf[NFSD4_REPLAY_ISIZE]) to store encoded operat…

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 112-byte inline buffer (rp_ibuf[NFSD4_REPLAY_ISIZE]) to store encoded operat…

▾ Abyssallinux · linux_kernelEPSS 0.58%via NVD
CVE-2026-28766Critical· 9.3PoC
5mo ago

A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.

A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.

▾ Abyssalmygardyn · cloud_apiEPSS 0.60%via NVD
CVE-2026-25197Critical· 9.1PoC
5mo ago

A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.

A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.

▾ Abyssalmygardyn · cloud_apiEPSS 0.29%via NVD
CVE-2026-33752High· 8.6PoC
5mo ago

curl_cffi: Redirect-based SSRF leads to internal network access in curl_cffi (with TLS impersonation bypass)

curl_cffi: Redirect-based SSRF leads to internal network access in curl_cffi (with TLS impersonation bypass)

▾ Midnightcurl-cffi · curl-cffiEPSS 0.45%via OSV
CVE-2025-10681High· 8.6PoC
5mo ago

Storage credentials are hardcoded in the mobile app and device firmware

Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end user permissions and do not expire within a reasonable amount of time. This vulnerability may grant unauthorized acces…

▾ MidnightEPSS 0.34%via NVD
CVE-2026-4350High· 8.1PoC
5mo ago

The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1

The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter…

▾ MidnightEPSS 0.53%via NVD
CVE-2026-32186Critical· 10.0
5mo ago

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · bingEPSS 0.90%via NVD
CVE-2026-35029HighPoC
5mo ago

LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint

LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint

▾ Midnightlitellm · litellmEPSS 4.0%via OSV
CVE-2026-23450Critical· 9.8
5mo ago

net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock()

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller reported a panic in smc_tcp_syn_recv_sock() [1]. smc_tcp_syn_recv_sock() is called in the T…

▾ MidnightLinux · LinuxEPSS 0.56%via CVEORG
CVE-2018-25237Critical· 9.8
5mo ago

Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication is enabled that allows remote attackers to crash the device or execute arbitrary code by…

Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication is enabled that allows remote attackers to crash the device or execute arbitrary code by…

▾ MidnightEPSS 0.82%via NVD
CVE-2018-25236Critical· 9.8
5mo ago

Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administ…

Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administ…

▾ MidnightEPSS 0.50%via NVD

Most-affected vendors

By CVEs published in the period.