VulnSea

Weekly digest

Week 17, 2026 (20–26 Apr)

152 new CVEs this week, in line with the recent average. Of those, 15 critical and 54 high. 16 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. Linux was the most-affected vendor with 43.

152
New CVEs
15
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 152 published.

CVE-2026-31431High· 7.8CISA KEVPoC
5mo ago

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in op…

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in op…

Abyssalredhat · openshift_container_platformEPSS 100%via NVD
CVE-2026-41176Critical· 9.8PoC
5mo ago

Rclone is a command-line program to sync files and directories to and from different cloud storage providers

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, includin…

Abyssalrclone · rcloneEPSS 33%via NVD
CVE-2026-41179Critical· 9.8PoC
5mo ago

RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution

RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution

Abyssalrclone · github.com/rclone/rcloneEPSS 8.6%via OSV
CVE-2026-41492Critical· 9.8PoC
5mo ago

Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars

Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars

Abyssaldgraph-io · github.com/dgraph-io/dgraph/v25EPSS 3.1%via OSV
CVE-2026-6951Critical· 9.8PoC
5mo ago

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the e…

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the e…

Abyssalsimple-git_project · simple-gitEPSS 0.88%via NVD
CVE-2026-33626High· 7.5PoC
5mo ago

LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading

LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading

Midnightlmdeploy · lmdeployEPSS 45%via OSV
CVE-2026-31669Critical· 9.8
5mo ago

mptcp: fix slab-use-after-free in __inet_lookup_established

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix slab-use-after-free in __inet_lookup_established The ehash table lookups are lockless and rely on SLAB_TYPESAFE_BY_RCU to guarantee socket memory stability …

MidnightLinux · LinuxEPSS 0.46%via CVEORG
CVE-2026-31649Critical· 9.8
5mo ago

net: stmmac: fix integer underflow in chain mode

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix integer underflow in chain mode The jumbo_frm() chain-mode implementation unconditionally computes len = nopaged_len - bmax; where nopaged_len =…

MidnightLinux · LinuxEPSS 0.46%via CVEORG
CVE-2026-31607Critical· 9.8
5mo ago

In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_submit() unconditionally overwrites ur…

In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_submit() unconditionally overwrites ur…

Midnightlinux · linux_kernelEPSS 0.31%via NVD
CVE-2026-3960Critical· 9.8
5mo ago

A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0…

A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due to insufficient security controls in the parameter blackl…

Midnighth2o · h2oEPSS 0.94%via OSV
CVE-2026-31533Critical· 9.8
5mo ago

net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption

In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption The -EBUSY handling in tls_do_encryption(), introduced by commit 859054147318 ("net: tls: handle …

MidnightLinux · LinuxEPSS 0.39%via CVEORG
CVE-2026-6235Critical· 9.8
5mo ago

The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20

The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. This is due to the plugin not properly verifying that a user …

MidnightEPSS 0.58%via NVD

Most-affected vendors

By CVEs published in the period.