Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 15 March 2026
RSS115 vulnerabilities published on 15 March 2026
Severity:
Underscore.js: Deep Recursion in flatten and isEqual Functions
OESA-2026-1580
A potentially serious security issue exists in older versions of the Underscore.js library. If a malicious user provides specially crafted data, it could cause the library to crash, making your websit...
Underscore.js versions before 1.13.8 can cause a website to crash
OESA-2026-1579
If your website uses an older version of the Underscore.js library, an attacker could potentially crash your site by passing in a specially crafted piece of data. To fix this, update to version 1.13.8...
Denial of Service in Underscore.js Before 1.13.8
OESA-2026-1578
A bug in older versions of the Underscore.js library can cause a website to run out of memory and become unresponsive if it processes a specially crafted input. This is a security risk because it coul...
Freetype: Out-of-bounds read in OpenType variable fonts
OESA-2026-1577
A security update is available for Freetype, a font rendering library, to fix a weakness that could allow attackers to read sensitive information from memory. Affected users should update to version 2...
Freetype OpenType Font Parsing Integer Overflow
OESA-2026-1576
Freetype library versions 2.13.2 and 2.13.3 have a security issue where a specific type of font file can cause the program to access memory outside its intended range. This could potentially allow an ...
Out-of-bounds read in Freetype variable font parser
OESA-2026-1575
The Freetype library in versions 2.13.2 and 2.13.3 has a bug that could allow a hacker to access sensitive memory. This affects systems that use variable fonts and could potentially allow unauthorized...
FreeType Library Can Crash When Parsing Certain Fonts
OESA-2026-1574
The FreeType library, used by some applications to render fonts, may crash when processing certain font files. This can happen if the font file contains malformed data. To fix this, update to the late...
Apache mod_security: Incorrect Charset Detection in Multipart Requests
OESA-2026-1573
A bug in the OWASP core rule set for Apache mod_security could allow attackers to evade some security checks. This affects older versions of the software, and updating to the latest version will fix t...
NGINX: Man-in-the-middle attackers can inject plain text into responses
OESA-2026-1572
NGINX users who proxy TLS traffic to other servers may be at risk of having sensitive data tampered with. This could lead to data integrity issues. To protect your systems, update to the latest versio...
NetworkManager update fixes security risk of unauthorized access
OESA-2026-1571
A vulnerability in NetworkManager allowed non-root users to access files owned by other users. This could potentially lead to unauthorized changes to network settings. To fix this issue, update Networ...
Linux Kernel UDP Socket Address Change Causes Connection Loss
OESA-2026-1570
A security update fixes a bug in the Linux Kernel that could cause connections to be lost when a UDP socket changes its local address while receiving data. This could happen when a server is changing ...
Linux Kernel Update Fixes GPSD Crash on Reboot
OESA-2026-1569
The Linux kernel has released an update to prevent GPSD from crashing when a device is rebooted. This update is important for systems that use GPSD, which is commonly used on devices such as GPS-enabl...
Linux Kernel Security Update: Prevents System Crash and Data Loss
OESA-2026-1568
A security update to the Linux Kernel prevents the operating system from crashing and losing data when accessing invalid memory locations or creating certain network interfaces. This update is importa...
Linux Kernel UDP Socket Address Change Can Cause Loss of Data
OESA-2026-1567
A security update is available for the Linux Kernel to fix a bug that can cause UDP socket connections to be lost if the server changes its local address while receiving data. This can happen when a s...
Linux Kernel Update Fixes UDP Socket Address Change Issue
OESA-2026-1566
A security update has been released for the Linux operating system to fix a bug that could allow a hacker to disrupt UDP communication between a server and a client. This issue occurs when a server ch...
Vim Update Needed to Fix Security Flaws in Command Line Editor
OESA-2026-1565
Vim users need to update to version 9.2.0073 or later to fix security issues that could allow hackers to run malicious commands or read sensitive information. If not updated, users may be vulnerable t...
Exiv2: Crash when reading crafted video files
OESA-2026-1564
Exiv2, a tool for managing image metadata, can crash if given a specially made video file. This is a security issue that can affect systems that use Exiv2. Update to version 0.28.8 or later to fix the...
libssh: Malicious Code Execution Through Remote Library
OESA-2026-1563
A security update is available for libssh, a library used by some programs to connect to remote servers. If not updated, attackers could potentially trick a program that uses libssh into running malic...
Outdated libssh Library Puts SSH Connections at Risk
OESA-2026-1562
A security update is available for the libssh library, which is used by some programs for secure remote connections. This update fixes multiple security issues that could allow an attacker to gain una...
libssh Security Update: Remote Code Execution Risk
OESA-2026-1561
Libssh, a library used by some software to connect to remote servers securely, has a security update to fix multiple vulnerabilities. These vulnerabilities could allow an attacker to take control of a...
Libssh: Remote Code Execution Through SFTP Extension
OESA-2026-1560
A bug in the SFTP extension of the libssh library can allow an attacker to execute malicious code on a remote system. This could happen if a programmer using libssh is tricked into accepting malicious...
libssh Library: Remote Code Execution and Data Exposure Risk
OESA-2026-1559
Libssh, a library used to connect to remote servers securely, has security issues that could allow attackers to execute code on your server or access sensitive data. This affects systems that use libs...
libssh: Remote code execution and data exposure risk
OESA-2026-1558
A security update is available for the libssh library, which is used by programmers to interact with remote computers securely. If not updated, attackers could potentially execute malicious code or ac...
Libsodium Encryption Library: Invalid Point Check
OESA-2026-1557
A security update is required for the encryption library Libsodium, as it incorrectly verifies certain types of encrypted data. This could allow an attacker to exploit the vulnerability in rare situat...
iOS Device Access Vulnerability in usbmuxd
OESA-2026-1556
A security update is available for usbmuxd, a program that helps manage connections to iOS devices. If not updated, a hacker can gain access to iOS devices connected to the same network, potentially a...