Daily digest
Saturday 11 April 2026
A quiet day: only 2 new CVEs against a recent average of about 72. Severity skewed high: 1 critical and 1 high, 100% of the total. One arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 2 that matter most of the 2 published.
CVE-2026-32146High· 7.8PoCImproper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download. Dependency names from gleam.toml and manifest.toml are incorporated into f…
Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download. Dependency names from gleam.toml and manifest.toml are incorporated into f…
CVE-2026-31845Critical· 9.3A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/tel/zadarma.php)
A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/tel/zadarma.php). The application directly reflects user-supplied input from the 'zd_ech…
Most-affected vendors
By CVEs published in the period.