VulnSea

Daily digest

Thursday 16 April 2026

A quiet day: only 31 new CVEs against a recent average of about 71. Of those, 2 critical and 10 high. One arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. weblate was the most-affected vendor with 5.

31
New CVEs
2
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 31 published.

CVE-2026-31843Critical· 9.8
5mo ago

The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files

The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. The endpoint is exposed v…

▾ MidnightEPSS 1.2%via NVD
CVE-2026-40173Critical· 9.4
5mo ago

Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints

Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints

▾ Midnightdgraph-io · github.com/dgraph-io/dgraph/v25EPSS 0.60%via OSV
CVE-2026-40611High· 8.8
5mo ago

ACME Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider

ACME Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider

▾ Twilightgo-acme · github.com/go-acme/lego/v4EPSS 0.55%via OSV
CVE-2026-2336High· 8.8
5mo ago

A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privil…

A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privil…

▾ Twilightmicrochip · istaxEPSS 0.23%via NVD
CVE-2025-54550High· 8.1
5mo ago

Apache Airflow: RCE by race condition in example_xcom dag

Apache Airflow: RCE by race condition in example_xcom dag

▾ Twilightapache-airflow · apache-airflowEPSS 0.58%via OSV
CVE-2026-41068High· 7.7
5mo ago

Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)

Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)

▾ Twilightkyverno · github.com/kyverno/kyvernoEPSS 0.37%via OSV
CVE-2026-40474High· 7.6
5mo ago

wger has Broken Access Control in Global Gym Configuration Update Endpoint

wger has Broken Access Control in Global Gym Configuration Update Endpoint

▾ Twilightwger · wgerEPSS 0.40%via OSV
CVE-2026-34242High· 7.7
5mo ago

Weblate: Arbitrary File Read via Symlink

Weblate: Arbitrary File Read via Symlink

▾ Twilightweblate · weblateEPSS 0.53%via OSV
CVE-2026-1880Medium· 5.4PoC
5mo ago

An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a …

An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a …

▾ TwilightASUS · DriverHubEPSS 0.14%via NVD
CVE-2026-41205High· 7.5
5mo ago

Mako: Path traversal via double-slash URI prefix in TemplateLookup

Mako: Path traversal via double-slash URI prefix in TemplateLookup

▾ Twilightmako · makoEPSS 0.53%via OSV
CVE-2026-41035High· 7.4
5mo ago

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configuratio…

▾ Twilightsamba · rsyncEPSS 0.49%via NVD
CVE-2026-31987High· 7.5
5mo ago

Apache Airflow: JWT token appearing in logs

Apache Airflow: JWT token appearing in logs

▾ Twilightapache-airflow · apache-airflowEPSS 0.83%via OSV

Most-affected vendors

By CVEs published in the period.