VulnSea

Daily digest

Friday 24 April 2026

A heavy day: 46 new CVEs, well above the recent average of about 21. Severity skewed high: 7 critical and 18 high, 54% of the total. 8 arrived with exploitation evidence or public exploit code already attached. Linux was the most-affected vendor with 17.

46
New CVEs
7
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 46 published.

CVE-2026-41492Critical· 9.8PoC
5mo ago

Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars

Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars

▾ Abyssaldgraph-io · github.com/dgraph-io/dgraph/v25EPSS 2.5%via OSV
CVE-2026-21515Critical· 9.9
5mo ago

Azure IoT Central Elevation of Privilege Vulnerability

Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure IOT CentralEPSS 0.70%via CVEORG
CVE-2026-31669Critical· 9.8
5mo ago

mptcp: fix slab-use-after-free in __inet_lookup_established

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix slab-use-after-free in __inet_lookup_established The ehash table lookups are lockless and rely on SLAB_TYPESAFE_BY_RCU to guarantee socket memory stability …

▾ MidnightLinux · LinuxEPSS 0.82%via CVEORG
CVE-2026-31649Critical· 9.8
5mo ago

net: stmmac: fix integer underflow in chain mode

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix integer underflow in chain mode The jumbo_frm() chain-mode implementation unconditionally computes len = nopaged_len - bmax; where nopaged_len =…

▾ MidnightLinux · LinuxEPSS 0.87%via CVEORG
CVE-2026-31607Critical· 9.8
5mo ago

In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_submit() unconditionally overwrites ur…

In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_submit() unconditionally overwrites ur…

▾ Midnightlinux · linux_kernelEPSS 0.44%via NVD
CVE-2026-42203HighPoC
5mo ago

LiteLLM: Server-Side Template Injection in /prompts/test endpoint

LiteLLM: Server-Side Template Injection in /prompts/test endpoint

▾ Midnightlitellm · litellmEPSS 0.66%via OSV
CVE-2026-42039High· 7.5PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process wi…

▾ Midnightaxios · axiosEPSS 0.97%via NVD
CVE-2026-42033High· 7.4PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) sil…

▾ Midnightaxios · axiosEPSS 0.92%via NVD
CVE-2026-42043High· 7.2PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to complet…

▾ Midnightaxios · axiosEPSS 0.58%via NVD
CVE-2026-41328Critical· 9.1
5mo ago

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field

▾ Midnightdgraph-io · github.com/dgraph-io/dgraph/v25EPSS 0.48%via OSV
CVE-2026-41327Critical· 9.1
5mo ago

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field

▾ Midnightdgraph-io · github.com/dgraph-io/dgraph/v25EPSS 0.47%via OSV
CVE-2026-42044Medium· 6.5PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's depend…

▾ Twilightaxios · axiosEPSS 0.86%via NVD

Most-affected vendors

By CVEs published in the period.