Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 21 March 2026
RSS152 vulnerabilities published on 21 March 2026
Severity:
OpenClaw versions before 2026.2.25 allow unauthorized event injection
CVE-2026-32899
Older versions of OpenClaw don't properly check events from certain sources. This means an attacker can trick the system into accepting events from users or channels they shouldn't have access to. Upd...
5.3
AVideo Server Filesystem Exposed to Unauthorized Access
GHSA-4wmm-6qxj-fpj4
CVE-2026-33238
An authenticated user can access and see files outside the intended video directory on the AVideo server. This could allow them to access sensitive information. To fix this, update the code to ensure ...
4.3
OpenClaw versions before 2026.2.22 may reveal gateway login secrets
CVE-2026-32897
Older versions of OpenClaw share a secret key with user IDs, making login information accessible to attackers. This means that if an attacker sees a prompt sent to a third-party model provider, they m...
6.3
OpenClaw (prior to 2026.2.26) allows attackers to bypass account approvals
CVE-2026-32067
If you use OpenClaw versions earlier than 2026.2.26, an attacker who has been approved to send messages in one account can send messages to another account without needing approval. This could allow u...
2.0
OpenClaw versions prior to 2026.2.25 allow unauthorized access to session status
CVE-2026-32050
Versions of OpenClaw before 2026.2.25 have a security issue that could let someone send unauthorized messages about a user's session status. This could be exploited by an attacker to access informatio...
6.3
Discourse: Unprivileged users can edit restricted tags
CVE-2026-33426
A security issue affects Discourse discussion platforms before versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2. Unprivileged users with tag-editing permissions could edit tags that they shouldn't h...
3.5
Keep Backup Daily plugin for WordPress: Unauthorized File Access
CVE-2026-3339
The Keep Backup Daily plugin for WordPress is vulnerable to unauthorized access to server files. Attackers with Administrator-level access can list the contents of any directory on the server. To prot...
2.7
Discourse: Unauthenticated attacker can trick users into visiting malicious sites
CVE-2026-33427
An attacker can trick Discourse users into visiting a fake website that looks like a legitimate Discourse authorization page, potentially stealing sensitive information or causing users to install mal...
2.7
OpenClaw versions prior to 2026.2.26: Approval Bypass via Reused Requests
CVE-2026-32058
Old versions of OpenClaw have a security weakness that lets attackers use previously approved requests with new environment settings, bypassing security checks. This can happen if an attacker gets hol...
2.0
BELL-CVE-2026-23267
BELL-CVE-2026-23267
Apache HTTP Server Allows Unauthorized File Access
BELL-CVE-2026-23266
An issue in Apache HTTP Server may allow attackers to access files they shouldn't. This affects Apache HTTP Server versions prior to 2.4.52. It's crucial to update to the latest version to prevent una...
Apache HTTP Server Cross-Site Scripting in URL Handling
BELL-CVE-2026-23265
A vulnerability in Apache's URL handling could allow an attacker to inject malicious code into websites. This could potentially allow an attacker to steal user data or take control of a website. Apach...
Apache HTTP Server Unsecured Configuration Data Exposure
BELL-CVE-2026-23264
Apache HTTP Server stores sensitive information in plain text, which can be accessed by unauthorized users. This is a concern for businesses that use Apache HTTP Server, as it may lead to unauthorized...
Apache Commons Text Deserialization Vulnerability in Spring Framework
BELL-CVE-2026-23263
A vulnerability in Apache Commons Text affects Spring Framework, potentially allowing an attacker to execute arbitrary code. This affects developers using Spring Framework. Update to the latest versio...
Adobe Acrobat Reader allows remote code execution via malicious PDF
BELL-CVE-2026-23245
Adobe Acrobat Reader has a security issue that could allow an attacker to run unauthorized code on your computer if they trick you into opening a malicious PDF file. This could lead to data theft, sys...
Adobe Flash Player allows unauthorized file access
BELL-CVE-2025-71270
Adobe Flash Player has a security issue that could allow attackers to access files on your computer without permission. This could lead to data theft or malware installation. Update Adobe Flash Player...
BELL-CVE-2025-71267
BELL-CVE-2025-71267
BELL-CVE-2025-71266
BELL-CVE-2025-71266
BELL-CVE-2025-71265
BELL-CVE-2025-71265
Adobe Acrobat Reader allows malicious PDF files to execute arbitrary code
BELL-CVE-2026-23278
A security issue in Adobe Acrobat Reader could allow an attacker to run unauthorized code on your computer if you open a malicious PDF file. This could lead to data theft, system compromise, or other ...
VMware vSphere Client Information Disclosure Vulnerability
BELL-CVE-2026-23275
A flaw in the VMware vSphere Client may allow unauthorized access to sensitive information. This issue affects organizations using VMware vSphere, potentially exposing confidential data. Update the vS...
Apache HTTP Server Unauthenticated Remote Code Execution Vulnerability
BELL-CVE-2026-23274
Apache HTTP Server has a vulnerability that allows an attacker to execute code on a server without needing a password. This means someone could potentially take control of the server, leading to data ...
Outdated Apache HTTP Server Can Allow Remote Code Execution
BELL-CVE-2026-23273
Apache HTTP Server versions 2.4.25 and older have a security issue that could allow an attacker to execute malicious code on a server. This is possible if a user visits a specially crafted website or ...
Apache HTTP Server Denial of Service (DoS) via Malicious Request
BELL-CVE-2026-23272
Apache HTTP Server is vulnerable to a denial of service attack that can crash the server. This could happen when the server receives a specially crafted request. Update your Apache HTTP Server to the ...
Apache HTTP Server Unrestricted Access to Sensitive Files
BELL-CVE-2026-23277
A vulnerability in the Apache HTTP Server allows an attacker to access sensitive files on a server by exploiting a misconfigured server. This could lead to unauthorized access to sensitive data, poten...