Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 24 March 2026

RSS

31 vulnerabilities published on 24 March 2026

Severity:
Woocommerce Custom Product Addons Pro plugin can run malicious code
CVE-2026-4001
An attacker can potentially execute code on your website by submitting a specially crafted value to a custom pricing field. This could allow them to access or modify sensitive data. Update to the late...
9.8
Arbitrary file read in Tekton Pipelines git resolver
GHSA-j5q5-j9gm-2w5c CVE-2026-33211 GO-2026-4761
A security issue in Tekton Pipelines git resolver allows an attacker with permission to create tasks or pipelines to read any file on the resolver pod's filesystem, which could lead to sensitive infor...
9.6
Graphiti: Unvalidated Input Lets Attackers Run Any Function
GHSA-3m5v-4xp5-gjg2 CVE-2026-33286
An attacker can exploit a security weakness in Graphiti's API to run any function on a database, potentially causing harm. This affects any Graphiti application that allows untrusted users to create, ...
9.1
Google Chrome Prior to 146.0.7680.165 Allows Malicious Code Execution
CVE-2026-4680
A bug in Google Chrome's FedCM feature can be exploited by a malicious website to run unauthorized code on your computer. This could potentially allow hackers to steal sensitive information or take co...
8.8
Jupiter X Core Plugin Allows Unauthorized File Uploads
CVE-2026-3533
The Jupiter X Core plugin for WordPress has a security issue that lets attackers with a subscriber-level account or higher upload malicious files. This could lead to code being run on the server or ma...
8.8
Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method and `Extractible` macro) do not enforce payload size limits before reading re...
GHSA-pp9r-xg4c-8j4x CVE-2026-33241
Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method and `Extractible` macro) do not enforce payload size limits before reading reque...
8.7
Spring Cloud: Files accessed unintentionally from wrong directories
CVE-2026-22739
Some Spring Cloud users may accidentally access files outside of the intended directory. This can happen when using the Config Server with the native file system backend. To fix this, update to Spring...
8.6
Contest Gallery Plugin Allows Admin Account Takeover in WordPress
CVE-2026-4021
The Contest Gallery plugin for WordPress has a security flaw that lets an attacker take control of any admin account without a password. This happens when a user with a special email address can trick...
8.1
LLM Model Software in C/C++ Fails to Validate Memory
CVE-2026-33298
A bug in a specific software that runs large language models allows an attacker to trick it into using too much memory, potentially letting them run malicious code. This can happen if the software pro...
7.8
Ella Core Crashes When Processing Malformed Location Report
GHSA-826q-wrq4-p23x CVE-2026-33282 GO-2026-4780
A specially crafted message to Ella Core can cause it to crash, disrupting services for all connected users. This can happen without any login or authentication. To fix this, the developers have made ...
7.5
Freeciv game crashes when receiving malicious internet traffic
CVE-2026-33250
Older versions of Freeciv game crash if sent fake data over the internet. This can let an attacker shut down public game servers, or crash the game on a player's computer. Upgrade to the latest versio...
7.5
Salvo is a Rust web framework. Versions 0.39.0 through 0.89.2 have a Path Traversal and Access Control Bypass vulnerability in the salvo-proxy component. The vulnerability allows an unauthenticated...
GHSA-f842-phm9-p4v4 CVE-2026-33242
Salvo is a Rust web framework. Versions 0.39.0 through 0.89.2 have a Path Traversal and Access Control Bypass vulnerability in the salvo-proxy component. The vulnerability allows an unauthenticated ex...
7.5
SourceCodester Patients Waiting Area Queue Management System: Unauthorized Access to Patient Data
CVE-2026-4617
A security weakness in SourceCodester Patients Waiting Area Queue Management System 1.0 allows unauthorized access to patient data. This could happen when a malicious person uses a remote attack, pote...
6.9
SourceCodester Online Catering Reservation SQL Injection
CVE-2026-4615
A security issue exists in SourceCodester Online Catering Reservation 1.0, specifically in the /search.php file. An attacker could manipulate data sent to this file, potentially allowing them to acces...
6.9
SourceCodester E-Commerce Site 1.0 Can Be Tricked into Revealing Sensitive Data
CVE-2026-4613
A security issue in SourceCodester E-Commerce Site 1.0 could allow an attacker to see sensitive information they shouldn't have access to. This is because the software doesn't properly check user inpu...
6.9
Go SDK HTTP Server Allows Arbitrary Post Requests Without Authentication
GHSA-89xv-2j6f-qhc8 CVE-2026-33252 GO-2026-4773
A security issue was found in a Go library that helps with HTTP communication. If not properly configured, an attacker could send unauthorized requests to a server, potentially triggering unwanted act...
7.1
Ella Core Crashes on Malformed NAS Messages
GHSA-3366-gw57-fcm5 CVE-2026-33283 GO-2026-4776
Ella Core is vulnerable to a crash when receiving specially crafted NAS messages. This can cause service disruption for all connected subscribers. To fix, software updates that add a security check fo...
6.5
Ella Core Crashes on Invalid NGAP Message IDs
GHSA-q669-4gmv-g8mf CVE-2026-33281 GO-2026-4783
Ella Core may crash if it receives a specially crafted NGAP message with an invalid PDU Session ID. This could cause a service disruption for connected subscribers. To protect against this, update Ell...
6.5
itsourcecode sanitize or validate this input 1.0: Unsanitized Input Leads to SQL Injection
CVE-2026-4614
The itsourcecode software has a weakness in how it handles input from users. This makes it possible for hackers to inject malicious code into the system, potentially allowing them to access sensitive ...
5.3
Dasel's YAML Parser Crashes System with Huge Input
GHSA-4fcp-jxh7-23x8 GO-2026-4768 CVE-2026-33320
Dasel's YAML parser can be exploited with an overly large YAML file, causing it to consume all available CPU and memory, freezing or crashing the system. This is due to a flaw in the way the parser ha...
6.2
WordPress User Registration & Membership Plugin Allows Unauthorized Access to Data
CVE-2026-4056
The User Registration & Membership plugin for WordPress has a security flaw that lets attackers with some access levels modify site rules, potentially exposing sensitive content or blocking legitimate...
5.4
JRuby Bcrypt Hashes Weakened by Integer Overflow
GHSA-f27w-vcwj-c954 CVE-2026-33306
A bug in the JRuby bcrypt implementation can make password hashes much weaker when using the cost setting of 31, allowing attackers to easily guess passwords. Affected applications should update to th...
4.5
WPGraphQL allows non-moderators to approve their own comments
CVE-2026-33290
A security update is available for WPGraphQL versions prior to 2.10.0. An authenticated user with limited privileges can approve their own comments, bypassing moderation workflows. Update to version 2...
4.3
Bolo-Blog 2.6.4: Remote Code Execution via Article Title
CVE-2026-4616
A security flaw in Bolo-Blog 2.6.4 allows hackers to inject malicious code into the system by manipulating article titles. This could let them access sensitive data or take control of your site. Updat...
4.8
Google Chrome: Malicious HTML can cause data corruption
CVE-2026-4679
A security issue in older versions of Google Chrome can allow a hacker to create a malicious website that corrupts data on your computer. This can happen if you visit the website. You should update to...