Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 24 March 2026
RSS48 vulnerabilities published on 24 March 2026
Severity:
Woocommerce Custom Product Addons Pro plugin can run malicious code
CVE-2026-4001
An attacker can potentially execute code on your website by submitting a specially crafted value to a custom pricing field. This could allow them to access or modify sensitive data. Update to the late...
9.8
Arbitrary file read in Tekton Pipelines git resolver
GHSA-j5q5-j9gm-2w5c
CVE-2026-33211
GO-2026-4761
A security issue in Tekton Pipelines git resolver allows an attacker with permission to create tasks or pipelines to read any file on the resolver pod's filesystem, which could lead to sensitive infor...
9.6
Graphiti: Unvalidated Input Lets Attackers Run Any Function
GHSA-3m5v-4xp5-gjg2
CVE-2026-33286
An attacker can exploit a security weakness in Graphiti's API to run any function on a database, potentially causing harm. This affects any Graphiti application that allows untrusted users to create, ...
9.1
Google Chrome Prior to 146.0.7680.165 Allows Malicious Code Execution
CVE-2026-4680
A bug in Google Chrome's FedCM feature can be exploited by a malicious website to run unauthorized code on your computer. This could potentially allow hackers to steal sensitive information or take co...
8.8
Google Chrome: Malicious HTML can cause data corruption
CVE-2026-4679
A security issue in older versions of Google Chrome can allow a hacker to create a malicious website that corrupts data on your computer. This can happen if you visit the website. You should update to...
8.8
Google Chrome: Remote code execution through crafted HTML page
CVE-2026-4678
A security weakness in Google Chrome's WebGPU feature allows a malicious website to execute unauthorized code on a user's device. This could potentially lead to data theft or other malicious activitie...
8.8
Google Chrome: Malicious websites can read sensitive memory
CVE-2026-4677
A security issue in older versions of Google Chrome could allow a malicious website to access sensitive information by manipulating audio content. This could potentially lead to data theft or other se...
8.8
Google Chrome: Malicious Web Page Can Escape Browser's Security Sandbox
CVE-2026-4676
An issue in older versions of Google Chrome allowed a malicious website to potentially break out of the browser's security sandbox. This could allow an attacker to access sensitive information or inst...
8.8
Google Chrome: Out-of-bounds memory read through crafted HTML page
CVE-2026-4675
Google Chrome versions before 146.0.7680.165 have a weakness that could allow an attacker to access sensitive information by tricking a user into visiting a malicious webpage. This means that a hacker...
8.8
Google Chrome: Malicious Websites Can Crash Your Browser
CVE-2026-4674
A security issue in Google Chrome allows malicious websites to cause a browser crash. This can happen when you visit a specially crafted web page. To stay safe, make sure to update Google Chrome to th...
8.8
Google Chrome: Untrusted web page can crash browser or steal data
CVE-2026-4673
An issue in Google Chrome's WebAudio feature could allow a malicious website to crash the browser or potentially steal sensitive information. This vulnerability affects versions of Chrome prior to 146...
8.8
Jupiter X Core Plugin Allows Unauthorized File Uploads
CVE-2026-3533
The Jupiter X Core plugin for WordPress has a security issue that lets attackers with a subscriber-level account or higher upload malicious files. This could lead to code being run on the server or ma...
8.8
Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method and `Extractible` macro) do not enforce payload size limits before reading re...
GHSA-pp9r-xg4c-8j4x
CVE-2026-33241
Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method and `Extractible` macro) do not enforce payload size limits before reading reque...
8.7
Spring Cloud: Files accessed unintentionally from wrong directories
CVE-2026-22739
Some Spring Cloud users may accidentally access files outside of the intended directory. This can happen when using the Config Server with the native file system backend. To fix this, update to Spring...
8.6
Contest Gallery Plugin Allows Admin Account Takeover in WordPress
CVE-2026-4021
The Contest Gallery plugin for WordPress has a security flaw that lets an attacker take control of any admin account without a password. This happens when a user with a special email address can trick...
8.1
LLM Model Software in C/C++ Fails to Validate Memory
CVE-2026-33298
A bug in a specific software that runs large language models allows an attacker to trick it into using too much memory, potentially letting them run malicious code. This can happen if the software pro...
7.8
Apache Mod_gnutls: Client Certificate Verification Can Crash Server
CVE-2026-33307
A bug in older versions of the Apache HTTPD TLS module Mod_gnutls can cause a server to crash when verifying client certificates. This happens when a client sends a long certificate chain. The bug has...
7.5
Ella Core Crashes When Processing Malformed Location Report
GHSA-826q-wrq4-p23x
CVE-2026-33282
GO-2026-4780
A specially crafted message to Ella Core can cause it to crash, disrupting services for all connected users. This can happen without any login or authentication. To fix this, the developers have made ...
7.5
Freeciv game crashes when receiving malicious internet traffic
CVE-2026-33250
Older versions of Freeciv game crash if sent fake data over the internet. This can let an attacker shut down public game servers, or crash the game on a player's computer. Upgrade to the latest versio...
7.5
Salvo is a Rust web framework. Versions 0.39.0 through 0.89.2 have a Path Traversal and Access Control Bypass vulnerability in the salvo-proxy component. The vulnerability allows an unauthenticated...
GHSA-f842-phm9-p4v4
CVE-2026-33242
Salvo is a Rust web framework. Versions 0.39.0 through 0.89.2 have a Path Traversal and Access Control Bypass vulnerability in the salvo-proxy component. The vulnerability allows an unauthenticated ex...
7.5
SourceCodester Online Library Management System SQL Injection Risk
CVE-2026-4624
The SourceCodester Online Library Management System may allow an attacker to inject malicious SQL code, potentially exposing sensitive data or allowing unauthorized access to the system. This can happ...
6.9
DefaultFuction CRM System Exposes Users to Remote Attack
CVE-2026-4623
A security issue in the DefaultFuction Customer Relationship Management System could allow hackers to trick the system into making unauthorized requests on the server. This could be done remotely, wit...
6.9
SourceCodester Patients Waiting Area Queue Management System: Unauthorized Access to Patient Data
CVE-2026-4617
A security weakness in SourceCodester Patients Waiting Area Queue Management System 1.0 allows unauthorized access to patient data. This could happen when a malicious person uses a remote attack, pote...
6.9
SourceCodester Online Catering Reservation SQL Injection
CVE-2026-4615
A security issue exists in SourceCodester Online Catering Reservation 1.0, specifically in the /search.php file. An attacker could manipulate data sent to this file, potentially allowing them to acces...
6.9
SourceCodester E-Commerce Site 1.0 Can Be Tricked into Revealing Sensitive Data
CVE-2026-4613
A security issue in SourceCodester E-Commerce Site 1.0 could allow an attacker to see sensitive information they shouldn't have access to. This is because the software doesn't properly check user inpu...
6.9