2026-04-27 to 2026-05-04

Weekly Security Digest

Comprehensive summary of vulnerabilities and security news from the past 7 days.

1053
New CVEs
84
Critical
377
High Severity
4
Added to KEV

Severity Distribution

CRITICAL 84 (8%)
HIGH 377 (36%)
MEDIUM 391 (37%)
LOW 28 (3%)

Quick Stats

Total CVEs Published 1053
CISA KEV Additions 4
Security News Articles 72
News Sources 4

🎯 High-Risk Vulnerabilities

Ranked by EPSS Score
CVE-2023-23752 MEDIUM ⚠️ KEV

An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints....

5.3
CVSS
94.5%
EPSS
CVE-2018-7600 CRITICAL ⚠️ KEV

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or com...

9.8
CVSS
94.5%
EPSS
CVE-2018-1000861 CRITICAL ⚠️ KEV

A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allo...

9.8
CVSS
94.5%
EPSS
CVE-2021-22986 CRITICAL ⚠️ KEV

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2...

9.8
CVSS
94.5%
EPSS
CVE-2017-1000353 CRITICAL ⚠️ KEV

Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers...

9.8
CVSS
94.5%
EPSS
CVE-2018-13379 CRITICAL ⚠️ KEV

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to ...

9.1
CVSS
94.5%
EPSS
CVE-2019-3396 CRITICAL ⚠️ KEV

The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 befo...

9.8
CVSS
94.5%
EPSS
CVE-2019-17558 HIGH ⚠️ KEV

Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velo...

7.5
CVSS
94.5%
EPSS
CVE-2020-1938 CRITICAL ⚠️ KEV

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HT...

9.8
CVSS
94.5%
EPSS
CVE-2019-2725 CRITICAL ⚠️ KEV

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable v...

9.8
CVSS
94.5%
EPSS

Last data sync: 2026-05-04T12:30:13.818587

Generated by InfoSecCenter Security Intelligence Hub