VulnSea

Daily digest

Wednesday 15 April 2026

A quiet day: only 32 new CVEs against a recent average of about 75. Severity skewed high: 6 critical and 11 high, 53% of the total. 2 arrived with exploitation evidence or public exploit code already attached. cisco was the most-affected vendor with 7.

32
New CVEs
6
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 32 published.

CVE-2026-20180Critical· 9.9PoC
5mo ago

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker mus…

▾ Abyssalcisco · identity_services_engineEPSS 6.0%via NVD
CVE-2026-20147Critical· 9.9
5mo ago

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have va…

▾ Midnightcisco · identity_services_engine_passive_identity_connectorEPSS 10%via NVD
CVE-2026-20186Critical· 9.9
5mo ago

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker mus…

▾ Midnightcisco · identity_services_engineEPSS 5.6%via NVD
CVE-2026-5189Critical· 9.8
5mo ago

CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute …

CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute …

▾ Midnightsonatype · nexus_repository_managerEPSS 0.62%via NVD
CVE-2026-0827High· 7.1PoC
5mo ago

During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authentica…

During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authentica…

▾ Midnightlenovo · diagnosticsEPSS 0.21%via NVD
CVE-2026-40575Critical· 9.1
5mo ago

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing

▾ Midnightoauth2-proxy · github.com/oauth2-proxy/oauth2-proxy/v7EPSS 0.73%via OSV
CVE-2025-41118Critical· 9.1
5mo ago

Pyroscope is an open-source continuous profiling database

Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS). If the database is configured to use Tencent COS as the storage backend, an attacke…

▾ Midnightgrafana · pyroscopeEPSS 0.41%via NVD
CVE-2024-53412High· 8.4
5mo ago

NietThijmen ShoppingCart: Command injection in the connect function

NietThijmen ShoppingCart: Command injection in the connect function

▾ TwilightNietThijmen · github.com/NietThijmen/ShoppingCartEPSS 0.56%via OSV
CVE-2026-34632High· 8.2
5mo ago

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. A low-privileged local attacker could have exploited thi…

▾ Twilightadobe · photoshop_set-up.exeEPSS 0.31%via NVD
CVE-2026-4145High· 7.8
5mo ago

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.

▾ Twilightlenovo · software_fixEPSS 0.21%via NVD
CVE-2026-5598High· 7.5
5mo ago

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, f…

▾ TwilightLegion of the Bouncy Castle Inc. · coreEPSS 0.96%via NVD
CVE-2026-5588High· 7.5
5mo ago

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Cast…

▾ TwilightLegion of the Bouncy Castle Inc. · bcpkixEPSS 0.69%via NVD

Most-affected vendors

By CVEs published in the period.