VulnSea

Weekly digest

Week 15, 2026 (6–12 Apr)

A heavy week: 413 new CVEs, well above the recent average of about 142. Severity skewed high: 33 critical and 197 high, 56% of the total. 30 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. google was the most-affected vendor with 58.

413
New CVEs
33
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 413 published.

CVE-2026-34197High· 8.8CISA KEVPoC
5mo ago

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web conso…

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web conso…

Abyssalapache · activemqEPSS 98%via NVD
CVE-2026-34486High· 7.5CISA KEVPoC
5mo ago

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to …

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to …

Abyssalapache · tomcatEPSS 99%via NVD
CVE-2026-4631Critical· 9.8PoC
5mo ago

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP r…

AbyssalEPSS 15%via NVD
CVE-2026-33439Critical· 9.8PoC
5mo ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP…

Abyssalopenidentityplatform · openamEPSS 10%via NVD
CVE-2025-62718Critical· 9.9PoC⚖ disputed
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a tra…

Abyssalaxios · axiosEPSS 1.2%via NVD
CVE-2026-3296Critical· 9.8PoC
5mo ago

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php…

AbyssalEPSS 3.5%via NVD
CVE-2026-34444Critical· 10.0PoC
5mo ago

Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr

Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr

Abyssallupa · lupaEPSS 0.61%via OSV
CVE-2026-33229Critical· 9.8PoC
5mo ago

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script right to bypass the sandboxing of the…

Abyssalxwiki · xwikiEPSS 0.54%via NVD
CVE-2026-2942Critical· 9.8PoC
5mo ago

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9. This makes it possible for…

AbyssalEPSS 0.58%via NVD
CVE-2025-69515Critical· 9.1PoC
5mo ago

An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device reporting an incorrect or static location.

An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device reporting an incorrect or static location.

AbyssalEPSS 0.46%via NVD
CVE-2026-35030Critical· 9.1PoC
5mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token[:20] as the cache key. JWT headers prod…

Abyssallitellm · litellmEPSS 0.63%via NVD
CVE-2026-5865High· 8.8PoC
5mo ago

Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Midnightgoogle · chromeEPSS 0.50%via NVD

Most-affected vendors

By CVEs published in the period.