VulnSea

Daily digest

Saturday 25 April 2026

A quiet day: only 7 new CVEs against a recent average of about 23. Severity skewed high: 2 critical and 2 high, 57% of the total. One arrived with exploitation evidence or public exploit code already attached. Linux was the most-affected vendor with 4.

7
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 7 that matter most of the 7 published.

CVE-2026-6951Critical· 9.8PoC
5mo ago

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the e…

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the e…

▾ Abyssalsimple-git_project · simple-gitEPSS 1.0%via NVD
CVE-2026-31682Critical· 9.1
5mo ago

bridge: br_nd_send: linearize skb before parsing ND options

In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: linearize skb before parsing ND options br_nd_send() parses neighbour discovery options from ns->opt[] and assumes that these options are in the li…

▾ MidnightLinux · LinuxEPSS 0.84%via CVEORG
CVE-2026-31680High· 7.8
5mo ago

net: ipv6: flowlabel: defer exclusive option free until RCU teardown

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: flowlabel: defer exclusive option free until RCU teardown `ip6fl_seq_show()` walks the global flowlabel hash under the seq-file RCU read-side lock and print…

▾ TwilightLinux · LinuxEPSS 0.18%via CVEORG
CVE-2026-31674High· 7.1
5mo ago

netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check()

In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() Reject rt match rules whose addrnr exceeds IP6T_RT_HOPS. rt_mt6() expects addrnr to stay within the boun…

▾ TwilightLinux · LinuxEPSS 0.17%via CVEORG
CVE-2026-31681Medium· 5.5
5mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_multiport: validate range encoding in checkentry ports_match_v1() treats any non-zero pflags entry as the start of a port range and unconditionally consu…

In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_multiport: validate range encoding in checkentry ports_match_v1() treats any non-zero pflags entry as the start of a port range and unconditionally consu…

▾ Sunlitlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-6993Medium· 5.3
5mo ago

go-kratos: go-kratos kratos: Information disclosure via unintended HTTP server intermediary (CVE-2026-6993)

A flaw was found in go-kratos kratos. A remote attacker could exploit a vulnerability in the HTTP server's `NewServer` function, specifically within the `http.DefaultServeMux Fallback Handler`. This manipulation creates an unintended inter…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.54%via CSAF
CVE-2026-6984Medium· 4.7
5mo ago

AstrBot has Incomplete Filtering of Special Elements

AstrBot has Incomplete Filtering of Special Elements

▾ Sunlitastrbot · astrbotEPSS 0.41%via OSV

Most-affected vendors

By CVEs published in the period.