VulnSea

Daily digest

Thursday 9 April 2026

37 new CVEs this day, in line with the recent average. Severity skewed high: 5 critical and 15 high, 54% of the total. 2 arrived with exploitation evidence or public exploit code already attached. juniper was the most-affected vendor with 7.

37
New CVEs
5
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 37 published.

CVE-2026-34486High· 7.5CISA KEVPoC
5mo ago

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to …

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to …

▾ Abyssalapache · tomcatEPSS 6.6%via NVD
CVE-2025-62718Critical· 9.9PoC⚖ disputed
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a tra…

▾ Abyssalaxios · axiosEPSS 1.2%via NVD
CVE-2026-33784Critical· 9.8
5mo ago

A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device. vLWC software images s…

A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device. vLWC software images s…

▾ Midnightjuniper · virtual_lightweight_collectorEPSS 0.48%via NVD
CVE-2026-39962Critical· 9.6
5mo ago

MISP is an open source threat intelligence and sharing platform

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special elements in an LDAP query in ApacheAuthenticate.php allows LDAP injection via an unsanitized username value when ApacheA…

▾ MidnightEPSS 0.66%via NVD
CVE-2026-34184Critical· 9.1
5mo ago

AlanWeb SCADA does not enforce authorization for some directories

AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the c…

▾ Midnighthydrosystem.poznan · control_systemEPSS 0.46%via NVD
CVE-2025-57735Critical· 9.1
5mo ago

Apache Airflow: JWT token still valid after logout

Apache Airflow: JWT token still valid after logout

▾ Midnightapache-airflow · apache-airflowEPSS 0.67%via OSV
CVE-2026-34185High· 8.8
5mo ago

AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters

AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database. …

▾ Twilighthydrosystem.poznan · control_systemEPSS 0.47%via NVD
CVE-2025-13914High· 8.7
5mo ago

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an att…

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an att…

▾ Twilightjuniper · apstraEPSS 0.30%via NVD
CVE-2023-54359High· 8.2
5mo ago

WordPress adivaha Travel Plugin 2.3 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'pid' GET parameter

WordPress adivaha Travel Plugin 2.3 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'pid' GET parameter. Attackers can send re…

▾ TwilightEPSS 0.27%via NVD
CVE-2026-33788High· 7.8
5mo ago

A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to …

A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to …

▾ Twilightjuniper · junosEPSS 0.17%via NVD
CVE-2026-29146High· 7.5
5mo ago

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 thr…

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 thr…

▾ Twilightapache · tomcatEPSS 2.9%via NVD
CVE-2026-1584High· 7.5
5mo ago

A flaw was found in gnutls

A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to…

▾ Twilightgnu · gnutlsEPSS 1.3%via NVD

Most-affected vendors

By CVEs published in the period.