VulnSea

Weekly digest

Week 14, 2026 (30 Mar – 5 Apr)

A heavy week: 407 new CVEs, well above the recent average of about 100. Severity skewed high: 50 critical and 158 high, 51% of the total. 32 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. linux was the most-affected vendor with 50.

407
New CVEs
50
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 407 published.

CVE-2026-5281High· 8.8CISA KEV0dayPoC
5mo ago

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

Abyssalgoogle · chromeEPSS 4.9%via NVD
CVE-2026-34156Critical· 9.9PoC
5mo ago

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a Node.js vm sandbox with …

Abyssalnocobase · nocobaseEPSS 35%via NVD
CVE-2026-0545Critical· 9.8PoC
5mo ago

In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled

In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job e…

Abyssallfprojects · mlflowEPSS 4.4%via NVD
CVE-2026-34976Critical· 10.0PoC
5mo ago

Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization

Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization

Abyssaldgraph-io · github.com/dgraph-io/dgraph/v25EPSS 2.0%via OSV
CVE-2026-33579Critical· 9.9PoC
5mo ago

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can…

Abyssalopenclaw · openclawEPSS 0.83%via NVD
CVE-2026-31402Critical· 9.8PoC
5mo ago

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 112-byte inline buffer (rp_ibuf[NFSD4_REPLAY_ISIZE]) to store encoded operat…

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 112-byte inline buffer (rp_ibuf[NFSD4_REPLAY_ISIZE]) to store encoded operat…

Abyssallinux · linux_kernelEPSS 0.95%via NVD
CVE-2026-34243Critical· 9.8PoC
5mo ago

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title)

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_comment.body directly inside a shell com…

Abyssalnjzjz · wenxianEPSS 2.2%via NVD
CVE-2026-34220Critical· 9.8PoC
5mo ago

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a SQL injection vulnerability when specially crafted objects are interpreted as raw SQL q…

Abyssalmikro-orm · mikroormEPSS 0.43%via NVD
CVE-2026-28766Critical· 9.3PoC
5mo ago

A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.

A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.

Abyssalmygardyn · cloud_apiEPSS 0.44%via NVD
CVE-2026-25197Critical· 9.1PoC
5mo ago

A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.

A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.

Abyssalmygardyn · cloud_apiEPSS 0.29%via NVD
CVE-2026-34227High· 8.8PoC
5mo ago

Sliver is a command and control framework that uses a custom Wireguard netstack

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beaco…

Midnightbishopfox · sliverEPSS 0.40%via NVD
CVE-2026-34040High· 8.4PoC
5mo ago

Moby: Moby: Authorization bypass vulnerability (CVE-2026-34040)

A flaw was found in Moby, an open-source container framework. This security vulnerability allows attackers to bypass authorization plugins (AuthZ), which are mechanisms designed to control access and permissions within the container enviro…

MidnightRed Hat · Multicluster Global Hub 1.4.9EPSS 9.1%via CSAF

Most-affected vendors

By CVEs published in the period.