VulnSea

Weekly digest

Week 11, 2026 (9–15 Mar)

A busier-than-usual week with 114 new CVEs (recent average about 95). Severity skewed high: 12 critical and 53 high, 57% of the total. 20 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. adobe was the most-affected vendor with 24.

114
New CVEs
12
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 114 published.

CVE-2025-67038Critical· 9.8CISA KEVPoC
6mo ago

An issue was discovered in Lantronix EDS5000 2.1.0.0R3

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This al…

Hadallantronix · eds5008_firmwareEPSS 19%via NVD
CVE-2026-31900Critical· 9.8PoC
6mo ago

Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, us…

Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use from the repository pyproject.toml. A mal…

Abyssalblack · blackEPSS 0.46%via OSV
CVE-2026-23813Critical· 9.8PoC
6mo ago

A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls

A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable res…

Abyssalhpe · arubaos-cxEPSS 0.74%via NVD
CVE-2026-26118High· 8.8PoC
6mo ago

Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network

Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network

MidnightAzure · Azure.McpEPSS 0.96%via OSV
CVE-2025-69219High· 8.8PoC
6mo ago

Apache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator

Apache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator

Midnightapache-airflow-providers-http · apache-airflow-providers-httpEPSS 0.69%via OSV
CVE-2026-31844High· 8.8PoC
6mo ago

An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functiona…

An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functiona…

Midnightkoha · kohaEPSS 0.37%via NVD
CVE-2026-27826High· 8.2PoC
6mo ago

MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers

MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers

Midnightmcp-atlassian · mcp-atlassianEPSS 14%via OSV
CVE-2026-0846High· 8.6PoC
6mo ago

Arbitrary File Read via Absolute Path Input in nltk.util.filestring()

A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without saniti…

Midnightnltk · nltk/nltkEPSS 0.43%via CVEORG
CVE-2026-32247High· 8.1PoC
6mo ago

Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters

Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters

Midnightgraphiti-core · graphiti-coreEPSS 0.34%via OSV
CVE-2026-24294High· 7.8PoC
6mo ago

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

Midnightmicrosoft · windows_10_1607EPSS 4.7%via NVD
CVE-2026-28384Critical· 9.9
6mo ago

An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints

An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This iss…

Midnightcanonical · lxdEPSS 0.65%via NVD
CVE-2026-27280High· 7.8PoC
6mo ago

DNG SDK versions 1.7.1 2471 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

DNG SDK versions 1.7.1 2471 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

Midnightadobe · dng_software_development_kitEPSS 0.21%via NVD

Most-affected vendors

By CVEs published in the period.