Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 16 March 2026

RSS

144 vulnerabilities published on 16 March 2026

Severity:
WordPress Plugin Allows Attackers to Manipulate Database Queries
CVE-2025-62319
An attacker can inject malicious code into a WordPress plugin's database queries, potentially allowing them to access sensitive information. This is a type of cyber attack that can happen if an attack...
9.8
Parse Server: Hackers can take over any user account
GHSA-5fw2-8jcv-xh87 CVE-2026-32248 BIT-parse-2026-32248
Parse Server's default setting for anonymous user sign-ups leaves accounts open to takeover by hackers. This can happen if the server is not configured to check user names properly. To fix this, updat...
9.1
Authlib JWS Forgery: Attackers Can Bypass Authentication
GHSA-wvwj-cvrp-7pv5 CVE-2026-27962
A security flaw in Authlib's JWS (JSON Web Signature) feature allows attackers to create fake tokens that can trick servers into accepting them as genuine. This bypasses authentication and authorizati...
9.1
Spinnaker clouddriver and orca allow malicious URLs with underscores
GHSA-8r8j-gfhg-fw38 CVE-2026-25534
Malicious URLs with underscores can bypass security checks in Spinnaker's clouddriver and orca components, allowing potential security breaches. This issue has been fixed in recent updates, and users ...
9.1
FastMCP OAuth Proxy issues tokens for wrong servers
GHSA-5h2m-4q8j-pqpj CVE-2025-69196
The FastMCP OAuth Proxy incorrectly issues tokens for the wrong server, not the one it's supposed to be protecting. This means an attacker can trick the proxy into issuing tokens for their own server,...
8.6
Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding
GHSA-m344-f55w-2m6j CVE-2026-28498
## 1. Executive Summary A critical library-level vulnerability was identified in the **Authlib** Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the interna...
8.2
Authlib Exposes Sensitive Data via Cryptographic Padding Oracle
GHSA-7432-952r-cw78 CVE-2026-28490
The Authlib library in certain configurations allows attackers to determine the validity of JSON Web Encryption (JWE) padding, potentially exposing sensitive data. This issue is present in any Authlib...
8.1
SOLIDWORKS Desktop: Malicious File Can Execute Code on Your Computer
CVE-2026-3476
A vulnerability in SOLIDWORKS Desktop can allow hackers to run malicious code on your computer if you open a specially crafted file. This could lead to your computer being compromised and your data at...
7.8
Uncontrolled Memory Allocation in DiceBear Converter
GHSA-v3r3-4qgc-vw66 CVE-2026-29112
The DiceBear Converter, used to generate avatars, can be forced to use up too much memory if it's given an SVG with very large width or height values. This can cause a server to become unresponsive. I...
7.5
Parse Server's OAuth2 adapter can validate wrong provider's tokens
GHSA-2cjm-2gwv-m892 CVE-2026-32242 BIT-parse-2026-32242
If you're using multiple OAuth2 providers with Parse Server, a bug can let a token be accepted even if it shouldn't be. This happens because the same instance of the OAuth2 adapter is used for all pro...
8.6
pyOpenSSL TLS connection bypass through unhandled exception
GHSA-vp96-hxj8-p424 CVE-2026-27448
A previous version of pyOpenSSL allowed an attacker to bypass security features by causing a callback function to crash. This has been fixed, so connections will now be rejected if the callback fails....
7.3
Red Hat vsftpd: Remote Code Execution from Unauthenticated Users
RHSA-2026:4554
A security update is available for vsftpd on Red Hat systems. This update addresses a security weakness that could allow an attacker to execute arbitrary commands on a server without permission. Users...
6.5
Critical Update Needed for vsftpd on Red Hat Servers
RHSA-2026:4553
A security update is available for vsftpd on Red Hat systems, addressing a critical issue that could allow unauthorized access if exploited. This means hackers could potentially gain access to your se...
6.5
Parse Server OAuth2 login issue with wrong token sent
CVE-2026-32269 GHSA-69xg-f649-w5g2 BIT-parse-2026-32269
The OAuth2 login feature in Parse Server has a problem that can cause login failures or allow unauthorized access. This affects systems that use the OAuth2 adapter with specific settings. To fix the i...
7.6
WP EasyPay Missing Authorization Allows Unintended Access
CVE-2026-32587
WP EasyPay, a plugin used for payment processing, has a security issue that allows unauthorized users to access sensitive features. This affects versions 1 through 4.2.11. To fix, update to version 4....
5.4
Modern Events Calendar: Unauthorized Access to Events
CVE-2026-32583
Certain security settings are not properly enforced, allowing unauthorized users to view or modify events they shouldn't have access to. This affects users of Modern Events Calendar, specifically thos...
5.3
INDEX Conferences App on Android Exposes Hard-Coded Credentials
CVE-2026-4219
The INDEX Conferences & Exhibitions Organization YWF BPOF APGCS App on Android devices has a security flaw that could allow an attacker to access sensitive information. This flaw is present in version...
1.9
Albert Health on Android Stores Credentials Unprotected
CVE-2026-4250
A security issue in the Albert Health app on Android means that sensitive information, like passwords and access keys, are stored in a way that can be easily accessed by attackers if they have access ...
2.0
LibreChat RAG API 0.7.0: Forged Log Entries Possible
CVE-2026-4276
Using LibreChat RAG API version 0.7.0, an attacker can manipulate log entries. This makes it difficult to trust the accuracy of the logs. Upgrade to a fixed version to prevent forged log entries.
OpenEDR 2.5.1.0 Driver Allows Local Privilege Escalation
CVE-2025-69784
A security flaw in the OpenEDR 2.5.1.0 kernel driver lets an unauthorized user, with normal user privileges, take control of the entire computer. This can happen if an attacker tricks the system into ...
OpenEDR 2.5.1.0: Local attacker can rename malicious executable to evade protection
CVE-2025-69783
A local attacker with malicious intent can rename a malicious file to mimic a trusted system process, potentially allowing them to access sensitive features of OpenEDR. This is a significant concern a...
NetBox 4.3.5: Malicious Comments Can Harm Others' Screens
CVE-2025-57543
An attacker can inject malicious comments into NetBox's comment field, which can be viewed by other users and potentially cause them to see incorrect or misleading information on the screen. This coul...
Adobe Acrobat Reader Can Crash When Opening Malformed Files
MINI-q2r9-vf3m-87xm
Adobe Acrobat Reader has a bug that can cause it to crash if you open a specially crafted PDF file. This is a serious issue because it can leave your computer open to other types of attacks. To stay s...
MINI-h66r-3x8w-689p
MINI-h66r-3x8w-689p
Microsoft Windows SMB Server Unsecured Data Exposure Risk
MINI-x7cq-f9vh-hp39
A bug in Microsoft Windows SMB Server can allow attackers to access sensitive data on a network. This could happen if an attacker can connect to the server and exploit the vulnerability. Update your s...