Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 16 March 2026
RSS175 vulnerabilities published on 16 March 2026
Severity:
Critical Update Needed for vsftpd on Red Hat Servers
RHSA-2026:4553
A security update is available for vsftpd on Red Hat systems, addressing a critical issue that could allow unauthorized access if exploited. This means hackers could potentially gain access to your se...
6.5
Parse Server OAuth2 login issue with wrong token sent
CVE-2026-32269
GHSA-69xg-f649-w5g2
BIT-parse-2026-32269
The OAuth2 login feature in Parse Server has a problem that can cause login failures or allow unauthorized access. This affects systems that use the OAuth2 adapter with specific settings. To fix the i...
7.6
SandboxJS allows one sandbox to exhaust another's resources
GHSA-7p5m-xrh7-769r
CVE-2026-32723
If multiple sandboxes share the same environment, a malicious sandbox can cause another sandbox to use up its CPU or memory allowance, leading to unexpected behavior or crashes. To fix this, update to...
6.3
Glances REST API and WebUI Remain Exposed to DNS Rebinding Attacks
GHSA-hhcg-r27j-fhv9
CVE-2026-32632
Glances' REST API and WebUI are still vulnerable to DNS rebinding attacks, which allow hackers to bypass browser security protections and access sensitive data. This is a separate issue from a previou...
5.9
AWS API MCP Server: Bypassing File Access Restrictions
CVE-2026-4270
An older version of the AWS API MCP Server software has a flaw that could allow unauthorized access to sensitive files. This could expose confidential information. To fix this, update to the latest ve...
6.8
WP EasyPay Missing Authorization Allows Unintended Access
CVE-2026-32587
WP EasyPay, a plugin used for payment processing, has a security issue that allows unauthorized users to access sensitive features. This affects versions 1 through 4.2.11. To fix, update to version 4....
5.4
Modern Events Calendar: Unauthorized Access to Events
CVE-2026-32583
Certain security settings are not properly enforced, allowing unauthorized users to view or modify events they shouldn't have access to. This affects users of Modern Events Calendar, specifically thos...
5.3
Memray HTML Reports Allow Attackers to Inject Malicious Code
GHSA-r5pr-887v-m2w9
CVE-2026-32722
Memray versions before 1.19.2 can insert malicious code into HTML reports, which can be executed when a user opens the report in a browser. This can happen if an attacker has control over the process ...
3.6
INDEX Conferences App on Android Exposes Hard-Coded Credentials
CVE-2026-4219
The INDEX Conferences & Exhibitions Organization YWF BPOF APGCS App on Android devices has a security flaw that could allow an attacker to access sensitive information. This flaw is present in version...
1.9
StudioCMS REST Users API Exposes Owner Account Details to Admins
GHSA-xvf4-ch4q-2m24
CVE-2026-32638
An issue in the StudioCMS REST API allows admins to see sensitive information about owner accounts, including IDs, usernames, display names, and email addresses. This is unexpected because the API is ...
2.7
CityData CityChat Android: Unprotected Storage of Credentials
CVE-2026-4251
The CityData CityChat app on Android stores sensitive credentials in an unprotected file. This means that if someone gains access to your device, they could potentially access your login information a...
2.0
Albert Health on Android Stores Credentials Unprotected
CVE-2026-4250
A security issue in the Albert Health app on Android means that sensitive information, like passwords and access keys, are stored in a way that can be easily accessed by attackers if they have access ...
2.0
pyOpenSSL TLS connection bypass through unhandled exception
GHSA-vp96-hxj8-p424
CVE-2026-27448
A previous version of pyOpenSSL allowed an attacker to bypass security features by causing a callback function to crash. This has been fixed, so connections will now be rejected if the callback fails....
1.7
GoBGP gobgpd v.4.2.0 Remote Denial of Service
CVE-2026-30405
A remote attacker can crash GoBGP's BGP daemon (gobgpd) by sending a specially crafted BGP message, making the system unavailable. This affects all systems running GoBGP gobgpd version 4.2.0. To fix, ...
gunet Open eClass v3.11 allows attackers to execute code via uploaded SVG file
CVE-2025-65734
A security issue in the Courses/Work Assignments module of gunet Open eClass v3.11 allows attackers to run malicious code on a website after uploading a specially crafted image file. This could potent...
No Known Vulnerability Associated with This Candidate
CVE-2025-54758
This vulnerability report has been rejected due to a lack of evidence linking it to a specific security issue. As a result, there is no identified risk to be concerned about. No action is required.
No Identified Vulnerability in Software
CVE-2025-53815
This is not a legitimate vulnerability report. It appears to be a rejected candidate number with no associated issue. No action is required.
No Known Vulnerability in [Unknown Software]
CVE-2025-53517
This candidate was not associated with a known vulnerability in 2025. However, since it's not clear what software or issue this pertains to, we can't provide further information or guidance. It's like...
Adobe Acrobat Reader Vulnerability Allows Remote Code Execution
MINI-rmjw-35g3-f9qj
Adobe Acrobat Reader users are at risk of having malicious code run on their computers if they open a specially crafted PDF file. This could lead to data theft, system compromise, or other malicious a...
Apache Log4j: Uncontrolled Deserialization in JNDI Lookups Can Lead to Remote Code Execution
CGA-fhc2-gph6-prwr
Log4j, a popular logging library used in many Java applications, contains a security weakness that could allow an attacker to inject malicious code and execute it on a server. This could potentially a...
CGA-77vp-4q83-qrv6
CGA-77vp-4q83-qrv6
MINI-x4q4-grrp-rr8j
MINI-x4q4-grrp-rr8j
MINI-j5r7-w9x8-9w4c
MINI-j5r7-w9x8-9w4c
LibreChat RAG API 0.7.0: Forged Log Entries Possible
CVE-2026-4276
Using LibreChat RAG API version 0.7.0, an attacker can manipulate log entries. This makes it difficult to trust the accuracy of the logs. Upgrade to a fixed version to prevent forged log entries.
OpenEDR 2.5.1.0 Driver Allows Local Privilege Escalation
CVE-2025-69784
A security flaw in the OpenEDR 2.5.1.0 kernel driver lets an unauthorized user, with normal user privileges, take control of the entire computer. This can happen if an attacker tricks the system into ...