VulnSea

Daily digest

Wednesday 29 April 2026

A quiet day: only 10 new CVEs against a recent average of about 23. Severity skewed high: 7 high, 70% of the total. One arrived with exploitation evidence or public exploit code already attached. ckan was the most-affected vendor with 3.

10
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 10 that matter most of the 10 published.

CVE-2026-42031HighPoC
5mo ago

CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`

CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`

▾ Midnightckan · ckanEPSS 2.2%via OSV
CVE-2026-42352High· 8.6
5mo ago

pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber

pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber

▾ Twilightpygeoapi · pygeoapiEPSS 0.56%via OSV
CVE-2026-7111High· 8.4
5mo ago

Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, getline, and getline_all methods invoke r…

Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, getline, and getline_all methods invoke r…

▾ TwilightEPSS 0.22%via NVD
CVE-2026-42198High· 7.5
5mo ago

pgjdbc is an open source postgresql JDBC Driver

pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to pe…

▾ Twilightpostgresql · postgresql_jdbc_driverEPSS 4.1%via NVD
CVE-2026-42351High· 7.5
5mo ago

pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider

pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider

▾ Twilightpygeoapi · pygeoapiEPSS 0.61%via OSV
CVE-2026-41643High· 7.5
5mo ago

GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE

GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE

▾ Twilightosrg · github.com/osrg/gobgp/v4EPSS 0.60%via OSV
CVE-2026-7404High· 7.3
5mo ago

mcpo-simple-server has a Path Traversal issue

mcpo-simple-server has a Path Traversal issue

▾ Twilightmcpo-simple-server · mcpo-simple-serverEPSS 0.59%via OSV
CVE-2026-41255Medium· 6.1
5mo ago

CKAN has CSRF exemption primed by anonymous requests

CKAN has CSRF exemption primed by anonymous requests

▾ Sunlitckan · ckanEPSS 0.14%via OSV
CVE-2026-41132Medium
5mo ago

CKAN has no certificate validation on STMP connection

CKAN has no certificate validation on STMP connection

▾ Sunlitckan · ckanEPSS 0.21%via OSV
CVE-2026-23773Medium· 4.3
5mo ago

Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability

Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side re…

▾ SunlitEPSS 0.24%via NVD

Most-affected vendors

By CVEs published in the period.