Daily digest
Thursday 30 April 2026
17 new CVEs this day, in line with the recent average. Of those, 2 critical and 6 high. 2 arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 12 that matter most of the 17 published.
CVE-2026-40280Critical· 9.3PoCGotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection
Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection
CVE-2025-14543Critical· 9.1Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking
Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before…
CVE-2026-40171High· 8.8Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
CVE-2026-3833Medium· 6.5PoCA flaw was found in gnutls
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `perm…
CVE-2025-14576High· 7.8Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick
Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than nat…
CVE-2026-42254HighHickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context Elevation
Hickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context Elevation
CVE-2026-33845High· 7.5A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may…
CVE-2026-7246High· 7.2Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pa…
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
CVE-2025-13030High· 7.1django-mdeditor is Missing Authentication for Critical Function
django-mdeditor is Missing Authentication for Critical Function
CVE-2026-7163Medium· 6.1A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrativ…
A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrativ…
CVE-2026-41016Medium· 5.9apache-airflow-providers-smtp: No certificate validation on SMTP STARTTLS connections in SMTP provider
apache-airflow-providers-smtp: No certificate validation on SMTP STARTTLS connections in SMTP provider
CVE-2026-7500Medium· 5.4When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled
When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write…
Most-affected vendors
By CVEs published in the period.