VulnSea

Weekly digest

Week 12, 2026 (16–22 Mar)

A busier-than-usual week with 107 new CVEs (recent average about 84). Severity skewed high: 10 critical and 60 high, 65% of the total. 15 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. Linux was the most-affected vendor with 14.

107
New CVEs
10
Critical
2
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 107 published.

CVE-2026-3085High· 8.80day
6mo ago

GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability

GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required…

Abyssalgstreamer · gstreamerEPSS 0.83%via NVD
CVE-2026-3083High· 8.80day
6mo ago

GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability

GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exp…

Abyssalgstreamer · gstreamerEPSS 0.81%via NVD
CVE-2026-3082High· 7.80day
6mo ago

GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability

GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required …

Abyssalgstreamer · gstreamerEPSS 0.79%via NVD
CVE-2026-2923High· 7.80day
6mo ago

GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability

GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to ex…

Abyssalgstreamer · gstreamerEPSS 0.73%via NVD
CVE-2026-2922High· 7.80day
6mo ago

GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability

GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required t…

Abyssalgstreamer · gstreamerEPSS 0.43%via NVD
CVE-2026-2921High· 7.80day
6mo ago

GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability

GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploi…

Abyssalgstreamer · gstreamerEPSS 0.87%via NVD
CVE-2026-2920High· 7.80day
6mo ago

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required …

Abyssalgstreamer · gstreamerEPSS 0.77%via NVD
CVE-2026-33186Critical· 9.1PoC
6mo ago

gRPC-Go is the Go language implementation of gRPC

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logi…

Abyssalgrpc · grpcEPSS 1.6%via NVD
CVE-2026-27962Critical· 9.1PoC
6mo ago

Authlib is a Python library which builds OAuth and OpenID Connect servers

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that…

Abyssalauthlib · authlibEPSS 0.55%via NVD
CVE-2025-71257High· 7.3PoC
6mo ago

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets. Unauthenticated remote attackers can…

Midnightbmc · footprintsEPSS 45%via NVD
CVE-2025-50881High· 8.8PoC
6mo ago

The `flow/admin/moniteur.php` script in Use It Flow administration website before 10.0.0 is vulnerable to Remote Code Execution

The `flow/admin/moniteur.php` script in Use It Flow administration website before 10.0.0 is vulnerable to Remote Code Execution. When handling GET requests, the script takes user-supplied input from the `action` URL parameter, performs i…

MidnightEPSS 0.61%via NVD
CVE-2026-33310High· 8.8PoC
6mo ago

Intake has a Command Injection via shell() Expansion in Parameter Defaults

Intake has a Command Injection via shell() Expansion in Parameter Defaults

Midnightintake · intakeEPSS 0.43%via OSV

Most-affected vendors

By CVEs published in the period.