VulnSea

Weekly digest

Week 13, 2026 (23–29 Mar)

A heavy week: 155 new CVEs, well above the recent average of about 87. Severity skewed high: 15 critical and 74 high, 57% of the total. 24 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. linux was the most-affected vendor with 26.

155
New CVEs
15
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 155 published.

CVE-2026-33634CriticalCISA KEVPoC
6mo ago

Trivy ecosystem supply chain was briefly compromised

Trivy ecosystem supply chain was briefly compromised

Hadalaquasecurity · github.com/aquasecurity/trivyEPSS 59%via OSV
CVE-2026-5027High· 8.8PoC
5mo ago

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

Midnightlangflow · langflowEPSS 36%via NVD
CVE-2026-0558Critical· 9.8PoC
5mo ago

A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through t…

A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not enforce authentication, unlike other f…

Abyssallollms · lollmsEPSS 1.9%via OSV
CVE-2026-33937Critical· 9.8PoC
5mo ago

Handlebars provides the power necessary to let users build semantic templates

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition to a template string. The `value` field of a `NumberLitera…

Abyssalhandlebarsjs · handlebarsEPSS 1.7%via NVD
CVE-2026-33701Critical· 9.8PoC
5mo ago

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data with…

Abyssallinuxfoundation · opentelemetry_instrumentation_for_javaEPSS 0.92%via NVD
CVE-2026-27876Critical· 9.1PoC
5mo ago

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE)

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future…

AbyssalEPSS 1.9%via NVD
CVE-2026-23921High· 8.8PoC
6mo ago

A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter

A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned dire…

Midnightzabbix · zabbixEPSS 3.5%via NVD
CVE-2026-22739High· 8.6PoC
6mo ago

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configu…

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configu…

Midnightvmware · spring_cloud_configEPSS 1.2%via NVD
CVE-2026-33980High· 8.3PoC
5mo ago

Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries

Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries

Midnightadx-mcp-server · adx-mcp-serverEPSS 0.40%via OSV
CVE-2026-33941High· 8.2PoC
5mo ago

Handlebars provides the power necessary to let users build semantic templates

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings — template file…

Midnighthandlebarsjs · handlebarsEPSS 0.29%via NVD
CVE-2026-1961High· 8.0PoC
6mo ago

A flaw was found in Foreman

A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vulnerability arises from the system's use of unsanitized hostname values from compute resou…

MidnightEPSS 1.4%via NVD
CVE-2026-0560High· 7.5PoC
5mo ago

A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/exp…

A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. The `_download_image_to_temp()` function in `backend/routers/files.py` fails …

Midnightlollms · lollmsEPSS 1.8%via OSV

Most-affected vendors

By CVEs published in the period.