VulnSea

Daily digest

Thursday 30 April 2026

17 new CVEs this day, in line with the recent average. Of those, 2 critical and 6 high. 2 arrived with exploitation evidence or public exploit code already attached.

17
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 17 published.

CVE-2026-40280Critical· 9.3PoC
5mo ago

Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection

Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection

▾ Abyssalgotenberg · github.com/gotenberg/gotenberg/v8EPSS 2.1%via OSV
CVE-2025-14543Critical· 9.1
5mo ago

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before…

▾ Midnightrti · connext_professionalEPSS 0.21%via NVD
CVE-2026-40171High· 8.8
5mo ago

Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS

Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS

▾ Twilightjupyter-notebook · @jupyter-notebook/help-extensionEPSS 0.66%via OSV
CVE-2026-3833Medium· 6.5PoC
5mo ago

A flaw was found in gnutls

A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `perm…

▾ Twilightgnu · gnutlsEPSS 0.89%via NVD
CVE-2025-14576High· 7.8
5mo ago

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than nat…

▾ Twilightqt · qtdeclarativeEPSS 0.22%via NVD
CVE-2026-42254High
5mo ago

Hickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context Elevation

Hickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context Elevation

▾ Twilighthickory-recursor · hickory-recursorEPSS 0.26%via OSV
CVE-2026-33845High· 7.5
5mo ago

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may…

▾ Twilightgnu · gnutlsEPSS 0.89%via NVD
CVE-2026-7246High· 7.2
5mo ago

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pa…

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.

▾ Twilightclick · clickEPSS 0.92%via OSV
CVE-2025-13030High· 7.1
5mo ago

django-mdeditor is Missing Authentication for Critical Function

django-mdeditor is Missing Authentication for Critical Function

▾ Twilightdjango-mdeditor · django-mdeditorEPSS 0.31%via OSV
CVE-2026-7163Medium· 6.1
5mo ago

A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrativ…

A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrativ…

▾ Sunlitredhat · multicluster_engine_for_kubernetesEPSS 0.20%via NVD
CVE-2026-41016Medium· 5.9
5mo ago

apache-airflow-providers-smtp: No certificate validation on SMTP STARTTLS connections in SMTP provider

apache-airflow-providers-smtp: No certificate validation on SMTP STARTTLS connections in SMTP provider

▾ Sunlitapache-airflow-providers-smtp · apache-airflow-providers-smtpEPSS 0.27%via OSV
CVE-2026-7500Medium· 5.4
5mo ago

When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled

When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write…

▾ SunlitEPSS 0.32%via NVD

Most-affected vendors

By CVEs published in the period.