VulnSea

Daily digest

Tuesday 7 April 2026

65 new CVEs this day, in line with the recent average. Severity skewed high: 9 critical and 30 high, 60% of the total. 11 arrived with exploitation evidence or public exploit code already attached. openssl was the most-affected vendor with 7.

65
New CVEs
9
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 65 published.

CVE-2026-34197High· 8.8CISA KEVPoC
5mo ago

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web conso…

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web conso…

▾ Abyssalapache · activemqEPSS 15%via NVD
CVE-2026-4631Critical· 9.8PoC
5mo ago

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP r…

▾ AbyssalEPSS 9.2%via NVD
CVE-2026-33439Critical· 9.8PoC
5mo ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP…

▾ Abyssalopenidentityplatform · openamEPSS 8.4%via NVD
CVE-2026-34444Critical· 10.0PoC
5mo ago

Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr

Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr

▾ Abyssallupa · lupaEPSS 0.80%via OSV
CVE-2025-69515Critical· 9.1PoC
5mo ago

An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device reporting an incorrect or static location.

An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device reporting an incorrect or static location.

▾ AbyssalEPSS 0.46%via NVD
CVE-2026-34078Critical· 10.0
5mo ago

Flatpak is a Linux application sandboxing and distribution framework

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts th…

▾ Midnightflatpak · flatpakEPSS 0.90%via NVD
CVE-2026-4277Critical· 9.8
5mo ago

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInlineModelAdmin`. Earlier, unsupported D…

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInlineModelAdmin`. Earlier, unsupported D…

▾ Midnightdjangoproject · djangoEPSS 0.60%via NVD
CVE-2026-39364High· 7.5PoC
5mo ago

Vite is a frontend tooling framework for JavaScript

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query par…

▾ Midnightvitejs · viteEPSS 1.5%via NVD
CVE-2026-39363High· 7.5PoC
5mo ago

Vite is a frontend tooling framework for JavaScript

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custo…

▾ Midnightvitejs · viteEPSS 2.6%via NVD
CVE-2026-31789Critical· 9.8
5mo ago

Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled…

Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled…

▾ Midnightopenssl · opensslEPSS 0.33%via NVD
CVE-2026-28808Critical· 9.8⚖ disputed
5mo ago

Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside Docum…

Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside Docum…

▾ Midnighterlang · erlang/inetsEPSS 0.77%via NVD
CVE-2026-1114Critical· 9.8
5mo ago

LoLLMs is vulnerable to Improper Access Control through weak secret key

LoLLMs is vulnerable to Improper Access Control through weak secret key

▾ Midnightlollms · lollmsEPSS 0.54%via OSV

Most-affected vendors

By CVEs published in the period.