VulnSea

Daily digest

Friday 17 April 2026

A quiet day: only 20 new CVEs against a recent average of about 50. Severity skewed high: 4 critical and 9 high, 65% of the total. One arrived with exploitation evidence or public exploit code already attached. hashicorp was the most-affected vendor with 3.

20
New CVEs
4
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 20 published.

CVE-2026-40477Critical· 9.0PoC
5mo ago

Thymeleaf is a server-side Java template engine for web and standalone environments

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanism…

▾ Abyssalthymeleaf · thymeleafEPSS 0.94%via NVD
CVE-2026-5720Critical· 9.1
5mo ago

miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote

miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote. Attacker…

▾ MidnightEPSS 1.1%via NVD
CVE-2026-40525Critical· 9.1
5mo ago

OpenViking: Unauthenticated remote bot control via OpenAPI HTTP routes

OpenViking: Unauthenticated remote bot control via OpenAPI HTTP routes

▾ Midnightopenviking · openvikingEPSS 0.76%via OSV
CVE-2026-40478Critical· 9.0
5mo ago

Thymeleaf is a server-side Java template engine for web and standalone environments

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mecha…

▾ Midnightthymeleaf · thymeleafEPSS 1.2%via NVD
CVE-2026-40066High· 8.8
5mo ago

Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded

Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and executes a script resulting in unauthenticated remote code execution.

▾ Twilightanviz · cx7_firmwareEPSS 0.54%via NVD
CVE-2026-41496High· 8.1
5mo ago

PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)

PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)

▾ Twilightpraisonai · praisonaiEPSS 0.41%via OSV
CVE-2026-41491High· 8.1
5mo ago

Dapr: Service Invocation path traversal ACL bypass

Dapr: Service Invocation path traversal ACL bypass

▾ Twilightdapr · github.com/dapr/daprEPSS 0.49%via OSV
CVE-2026-6507High· 7.5
5mo ago

A flaw was found in dnsmasq

A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` opt…

▾ TwilightEPSS 0.58%via NVD
CVE-2026-5807High· 7.5
5mo ago

HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations

HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations

▾ Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.91%via OSV
CVE-2026-4525High· 7.5
5mo ago

HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization

HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization

▾ Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.59%via OSV
CVE-2026-40476High· 7.5
5mo ago

graphql-go is a Go implementation of GraphQL

graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCanBeMerged validation rule performs O(n²) pairwise comparisons of fields sharing the same response name. An attacker can send a query with…

▾ Twilightwebonyx · graphql-phpEPSS 0.73%via NVD
CVE-2026-40293High· 7.5
5mo ago

OpenFGA: github.com/openfga/openfga: OpenFGA: Information disclosure of preshared API key via playground endpoint (CVE-2026-40293)

A flaw was found in OpenFGA, an authorization/permission engine. When OpenFGA is configured to use preshared-key authentication and the built-in playground is enabled and accessible beyond localhost or trusted networks, a remote attacker c…

▾ TwilightRed Hat · Multicluster Global Hub 1.7.3EPSS 0.50%via CSAF

Most-affected vendors

By CVEs published in the period.