VulnSea

Daily digest

Saturday 4 April 2026

35 new CVEs this day, in line with the recent average. Severity skewed high: 1 critical and 21 high, 63% of the total. One arrived with exploitation evidence or public exploit code already attached. mybb was the most-affected vendor with 3.

35
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 35 published.

CVE-2016-20052Critical· 9.8
5mo ago

Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory

Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can upload malicious PHP files through the…

▾ Midnightsnewscms · snewsEPSS 0.95%via NVD
CVE-2026-40072High· 7.2PoC
5mo ago

web3.py: SSRF via CCIP Read (EIP-3668) OffchainLookup URL handling

web3.py: SSRF via CCIP Read (EIP-3668) OffchainLookup URL handling

▾ Midnightweb3 · web3EPSS 0.31%via OSV
CVE-2026-35463High· 8.8
5mo ago

pyLoad: Improper Neutralization of Special Elements used in an OS Command

pyLoad: Improper Neutralization of Special Elements used in an OS Command

▾ Twilightpyload-ng · pyload-ngEPSS 0.91%via OSV
CVE-2018-25255High· 8.4
5mo ago

10-Strike LANState 8.8 contains a local buffer overflow vulnerability in structured exception handling that allows local attackers to execute arbitrary code by crafting malicious LSM map files

10-Strike LANState 8.8 contains a local buffer overflow vulnerability in structured exception handling that allows local attackers to execute arbitrary code by crafting malicious LSM map files. Attackers can create a specially formatted …

▾ TwilightEPSS 0.18%via NVD
CVE-2026-4896High· 8.1
5mo ago

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via multiple AJAX action…

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via multiple AJAX action…

▾ TwilightEPSS 0.49%via NVD
CVE-2016-20061High· 7.8
5mo ago

sheed AntiVirus 2.3 contains an unquoted service path vulnerability in the ShavProt service that allows local attackers to escalate privileges by exploiting the service binary path

sheed AntiVirus 2.3 contains an unquoted service path vulnerability in the ShavProt service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can insert a malicious executable in the unqu…

▾ TwilightEPSS 0.12%via NVD
CVE-2016-20060High· 7.8
5mo ago

Hotspot Shield 6.0.3 contains an unquoted service path vulnerability in the hshld service binary that allows local attackers to escalate privileges by injecting malicious executables

Hotspot Shield 6.0.3 contains an unquoted service path vulnerability in the hshld service binary that allows local attackers to escalate privileges by injecting malicious executables. Attackers can place executable files in the service p…

▾ TwilightEPSS 0.15%via NVD
CVE-2016-20059High· 7.8
5mo ago

IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges

IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attackers can insert a malicious executable file in the unquoted…

▾ Twilightiobit · malware_fighterEPSS 0.18%via NVD
CVE-2016-20058High· 7.8
5mo ago

Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges

Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges. Attackers can place a malicious executable in …

▾ Twilightnetgate · amiti_antivirusEPSS 0.72%via NVD
CVE-2016-20057High· 7.8
5mo ago

NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to escalate privileges by exploiting the service binary path

NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious …

▾ Twilightnetgate · registry_cleanerEPSS 0.61%via NVD
CVE-2016-20056High· 7.8
5mo ago

Spy Emergency build 23.0.205 contains an unquoted service path vulnerability in the SpyEmrgHealth and SpyEmrgSrv services that allows local attackers to escalate privileges by inserting malicious executables

Spy Emergency build 23.0.205 contains an unquoted service path vulnerability in the SpyEmrgHealth and SpyEmrgSrv services that allows local attackers to escalate privileges by inserting malicious executables. Attackers can place executab…

▾ TwilightEPSS 0.15%via NVD
CVE-2016-20055High· 7.8
5mo ago

IObit Advanced SystemCare 10.0.2 contains an unquoted service path vulnerability in the AdvancedSystemCareService10 service that allows local attackers to escalate privileges

IObit Advanced SystemCare 10.0.2 contains an unquoted service path vulnerability in the AdvancedSystemCareService10 service that allows local attackers to escalate privileges. Attackers can place a malicious executable in the service pat…

▾ Twilightiobit · advanced_system_careEPSS 0.18%via NVD

Most-affected vendors

By CVEs published in the period.