VulnSea

Daily digest

Wednesday 8 April 2026

A heavy day: 198 new CVEs, well above the recent average of about 66. Severity skewed high: 14 critical and 93 high, 54% of the total. 8 arrived with exploitation evidence or public exploit code already attached. google was the most-affected vendor with 57.

198
New CVEs
14
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 198 published.

CVE-2026-33229Critical· 9.8PoC
5mo ago

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script right to bypass the sandboxing of the…

▾ Abyssalxwiki · xwikiEPSS 1.2%via NVD
CVE-2026-3296Critical· 9.8PoC
5mo ago

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php…

▾ AbyssalEPSS 3.0%via NVD
CVE-2026-2942Critical· 9.8PoC
5mo ago

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9. This makes it possible for…

▾ AbyssalEPSS 1.1%via NVD
CVE-2026-40035Critical· 9.1PoC
5mo ago

Unfurl - Werkzeug Debugger Exposure via String Config Parsing

Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a string and passed directly to app.run(), causing any non-em…

▾ Abyssalobsidianforensics · dfir-unfurlEPSS 0.72%via CVEORG
CVE-2026-5865High· 8.8PoC
5mo ago

Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.45%via NVD
CVE-2026-5902Critical· 9.8
5mo ago

Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media stream metadata via a crafted HTML page

Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media stream metadata via a crafted HTML page. (Chromium security severity: Low)

▾ Midnightgoogle · chromeEPSS 0.33%via NVD
CVE-2026-39892Critical· 9.8⚖ disputed
5mo ago

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this …

▾ Midnightcryptography.io · cryptographyEPSS 0.76%via NVD
CVE-2026-33088Critical· 9.8
5mo ago

Movable Type provided by Six Apart Ltd

Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement.

▾ Midnightsixapart · movable_typeEPSS 0.45%via NVD
CVE-2026-27143Critical· 9.8
5mo ago

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.

▾ Midnightgolang · goEPSS 0.66%via NVD
CVE-2026-25776Critical· 9.8
5mo ago

Movable Type provided by Six Apart Ltd

Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script.

▾ Midnightsixapart · movable_typeEPSS 0.73%via NVD
CVE-2026-23869High· 7.5PoC
5mo ago

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.…

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.…

▾ MidnightEPSS 1.6%via NVD
CVE-2025-52221Critical· 9.8
5mo ago

Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameters.

Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameters.

▾ Midnighttenda · ac6_firmwareEPSS 0.39%via NVD

Most-affected vendors

By CVEs published in the period.