VulnSea

Daily digest

Monday 6 April 2026

A busier-than-usual day with 69 new CVEs (recent average about 53). Severity skewed high: 2 critical and 40 high, 61% of the total. 4 arrived with exploitation evidence or public exploit code already attached. tenda was the most-affected vendor with 7.

69
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 69 published.

CVE-2026-35030Critical· 9.1PoC
5mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token[:20] as the cache key. JWT headers prod…

▾ Abyssallitellm · litellmEPSS 0.88%via NVD
CVE-2026-34977Critical· 9.8
5mo ago

Aperi'Solve is an open-source steganalysis web platform

Aperi'Solve is an open-source steganalysis web platform. In versions 3.1.3 through 3.2.0, when uploading a JPEG, a user can specify an optional password to accompany the JPEG. This password is then directly passed into an expect command,…

▾ MidnightEPSS 1.2%via NVD
CVE-2026-35172High· 7.5PoC
5mo ago

Distribution is a toolkit to pack, ship, store, and deliver container content

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: t…

▾ Midnightdistribution · distributionEPSS 0.67%via NVD
CVE-2026-5709High· 8.8
5mo ago

Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via craft…

Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via craft…

▾ Twilightamazon · research_and_engineering_studioEPSS 0.98%via NVD
CVE-2026-5708High· 8.8
5mo ago

Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to escalate privileges, assume the virtual…

Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to escalate privileges, assume the virtual…

▾ Twilightamazon · research_and_engineering_studioEPSS 0.74%via NVD
CVE-2026-5707High· 8.8
5mo ago

Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as roo…

Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as roo…

▾ Twilightamazon · research_and_engineering_studioEPSS 0.98%via NVD
CVE-2026-5687High· 8.8
5mo ago

A weakness has been identified in Tenda CX12L 16.03.53.12

A weakness has been identified in Tenda CX12L 16.03.53.12. This issue affects the function fromNatStaticSetting of the file /goform/NatStaticSetting. This manipulation of the argument page causes stack-based buffer overflow. The attack m…

▾ Twilighttenda · cx12l_firmwareEPSS 0.99%via NVD
CVE-2026-5686High· 8.8
5mo ago

A security flaw has been discovered in Tenda CX12L 16.03.53.12

A security flaw has been discovered in Tenda CX12L 16.03.53.12. This vulnerability affects the function fromRouteStatic of the file /goform/RouteStatic. The manipulation of the argument page results in stack-based buffer overflow. The at…

▾ Twilighttenda · cx12l_firmwareEPSS 0.99%via NVD
CVE-2026-5685High· 8.8
5mo ago

A vulnerability was identified in Tenda CX12L 16.03.53.12

A vulnerability was identified in Tenda CX12L 16.03.53.12. This affects the function fromAddressNat of the file /goform/addressNat. The manipulation of the argument page leads to stack-based buffer overflow. The attack can be initiated r…

▾ Twilighttenda · cx12l_firmwareEPSS 0.99%via NVD
CVE-2026-5629High· 8.8
5mo ago

A vulnerability was detected in Belkin F9K1015 1.00.10

A vulnerability was detected in Belkin F9K1015 1.00.10. The affected element is the function formSetFirewall of the file /goform/formSetFirewall. The manipulation of the argument webpage results in stack-based buffer overflow. The attack…

▾ Twilightbelkin · f9k1015_firmwareEPSS 1.1%via NVD
CVE-2026-5628High· 8.8
5mo ago

A security vulnerability has been detected in Belkin F9K1015 1.00.10

A security vulnerability has been detected in Belkin F9K1015 1.00.10. Impacted is the function formSetSystemSettings of the file /goform/formSetSystemSettings of the component Setting Handler. The manipulation of the argument webpage lea…

▾ Twilightbelkin · f9k1015_firmwareEPSS 1.1%via NVD
CVE-2026-5614High· 8.8
5mo ago

A security flaw has been discovered in Belkin F9K1015 1.00.10

A security flaw has been discovered in Belkin F9K1015 1.00.10. Impacted is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument webpage results in stack-based buffer overflow. The attack may …

▾ Twilightbelkin · f9k1015_firmwareEPSS 1.5%via NVD

Most-affected vendors

By CVEs published in the period.