Common Vulnerabilities and Exposures (CVE)

CVE-2026-34218

Mar 31, 2026 15:13:03 UTC

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.14, two related startup defects created a window during which only the single compile-time baseline rule was enforced ...

CVE-2026-32845

Mar 31, 2026 15:12:59 UTC

cgltf version 1.15 and prior contain an integer overflow vulnerability in the cgltf_validate() function when validating sparse accessors that allows attackers to trigger out-of-bounds reads by supplying crafted glTF/GLB input files with att...

CVE-2026-4964

Mar 31, 2026 15:11:01 UTC

A security vulnerability has been detected in letta-ai letta 0.16.4. This vulnerability affects the function _convert_message_create_to_message of the file letta/helpers/message_helper.py of the component File URL Handler. Such manipulation...

CVE-2026-34245

Mar 31, 2026 15:10:30 UTC

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/PlayLists/View/Playlists_schedules/add.json.php` endpoint allows any authenticated user with streaming permission to create or modify broadcast ...

CVE-2026-4959

Mar 31, 2026 15:09:19 UTC

A vulnerability was found in OpenBMB XAgent 1.0.0. This impacts the function check_user of the file XAgentServer/application/websockets/share.py of the component ShareServer WebSocket Endpoint. Performing a manipulation of the argument inte...

CVE-2026-32984

Mar 31, 2026 15:08:54 UTC

Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed heap data by sending specially crafted input. Attackers can exploit this vulnerability to trigger a denial of service c...

CVE-2026-34574

Mar 31, 2026 15:08:31 UTC

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.69 and 9.7.0-alpha.14, an authenticated user can bypass the immutability guard on session fields (expiresAt, creat...

CVE-2026-29870

Mar 31, 2026 15:08:04 UTC

A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file writes via the checkpoint_dir parameter in OfflineACE.run. The save_to_file method in ace/skillbook.py fails to normalize o...

CVE-2026-27879

Mar 31, 2026 15:02:59 UTC

A resample query can be used to trigger out-of-memory crashes in Grafana.

CVE-2026-28375

Mar 31, 2026 15:01:14 UTC

A testdata data-source can be used to trigger out-of-memory crashes in Grafana.

CVE-2026-3881

Mar 31, 2026 14:57:52 UTC

The Performance Monitor WordPress plugin through 1.0.6 does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attacks

CVE-2025-15617

Mar 31, 2026 14:34:15 UTC

Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to extract the GITHUB_TOKEN from uploaded artifacts. Attackers can use the exposed token within a limited time window to perf...

CVE-2026-34162

Mar 31, 2026 14:33:31 UTC

FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. This endpoint acts as a full HTTP proxy — it accepts a use...

CVE-2026-34200

Mar 31, 2026 14:30:36 UTC

Nhost is an open source Firebase alternative with GraphQL. Prior to version 1.41.0, The Nhost CLI MCP server, when explicitly configured to listen on a network port, applies no inbound authentication and does not enforce strict CORS. This a...

CVE-2026-33979

Mar 31, 2026 14:29:43 UTC

Express XSS Sanitizer is Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to prevent Cross Site Scripting (XSS) attack. A vulnerability has been identified in versions prior...