VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-42127High· 7.5
3mo ago

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of serv…

▾ Twilightgrafana · grafanaEPSS 0.43%via NVD
CVE-2026-9029High· 7.3
3mo ago

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored…

▾ Twilightgrafana · grafanaEPSS 0.32%via NVD
CVE-2026-42129High· 7.7
3mo ago

A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.

A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.

▾ Twilightgrafana · loki_datasourceEPSS 0.44%via NVD
CVE-2026-10601Medium· 5.4
3mo ago

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak inter…

▾ Sunlitgrafana · grafanaEPSS 0.29%via NVD
CVE-2026-47155Medium· 6.5
3mo ago

vllm: vLLM: Supply-chain integrity issue due to inconsistent revision pinning controls (CVE-2026-47155)

A flaw was found in vLLM, an inference and serving engine for large language models (LLMs). The revision pinning controls in vLLM do not consistently apply to all artifacts loaded for a model. This allows a deployment configured with speci…

▾ SunlitRed Hat · Red Hat Enterprise Linux AI 3.3EPSS 0.25%via CSAF
CVE-2026-53550Medium· 5.3
3mo ago

js-yaml: js-yaml: Denial of Service via crafted YAML merge keys (CVE-2026-53550)

A flaw was found in js-yaml, a JavaScript YAML parser and dumper. A remote attacker can exploit this vulnerability by providing a specially crafted YAML document that repeatedly uses the same alias in a merge sequence. This can lead to alg…

▾ SunlitRed Hat · Red Hat Openshift Data Foundation 4.18EPSS 0.41%via CSAF
CVE-2026-54276Medium· 6.1
3mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vuln…

▾ Sunlitaiohttp · aiohttpEPSS 0.31%via NVD
CVE-2026-54280High· 7.5⚖ disputed
3mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar…

▾ Twilightaiohttp · aiohttpEPSS 0.46%via NVD
CVE-2026-54283High· 7.5
3mo ago

starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS (CVE-2026-54283)

A flaw was found in Starlette where the request.form() method silently ignores configured resource limits (max_fields and max_part_size) when parsing application/x-www-form-urlencoded data. An unauthenticated attacker can exploit this by s…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.48%via CSAF
CVE-2026-54293High· 7.5PoC
3mo ago

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to path tr…

▾ Midnightnltk · nltkEPSS 0.63%via NVD
CVE-2026-41523High· 7.5
3mo ago

vllm: vLLM: Arbitrary code execution via malicious HuggingFace model (CVE-2026-41523)

A flaw was found in vLLM, an inference and serving engine for large language models (LLMs). An unauthenticated attacker can exploit an assert-based security check during activation function loading. By publishing a malicious HuggingFace mo…

▾ TwilightRed Hat · Red Hat AI Inference Server 3.4EPSS 0.91%via CSAF
CVE-2026-48746Critical· 9.1PoC
3mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API Authenti…

▾ Abyssalvllm · vllmEPSS 1.2%via NVD
CVE-2024-37155Medium· 6.5
3mo ago

OpenCTI May Bypass Introspection Restriction

OpenCTI May Bypass Introspection Restriction

▾ Sunlitpycti · pyctiEPSS 0.46%via GHSA
CVE-2025-64719Medium· 4.9
3mo ago

Gogs has a Denial of Service in repository/wiki file listing web pages

Gogs has a Denial of Service in repository/wiki file listing web pages

▾ Sunlitgogs · gogs.io/gogsEPSS 0.44%via GHSA
CVE-2026-21887High· 7.7
3mo ago

OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature

OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature

▾ Twilightpycti · pyctiEPSS 0.21%via GHSA
CVE-2026-25119High
3mo ago

Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers

Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers

▾ Twilightgogs · gogs.io/gogsEPSS 0.86%via GHSA
CVE-2026-31978Medium· 6.5
3mo ago

motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint

motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint

▾ Sunlitmotioneye · motioneyeEPSS 0.42%via GHSA
CVE-2026-32315Medium· 5.5
3mo ago

motionEye's World-Readable Configuration File Exposes Admin Password Hash

motionEye's World-Readable Configuration File Exposes Admin Password Hash

▾ Sunlitmotioneye · motioneyeEPSS 2.9%via GHSA
CVE-2026-33646Critical· 9.6
3mo ago

Mise Vulnerable to Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)

Mise Vulnerable to Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)

▾ Midnightmise · miseEPSS 0.69%via GHSA
CVE-2026-33684Medium· 5.3
3mo ago

AVideo's Privilege Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions

AVideo's Privilege Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions

▾ Sunlitwwbn · wwbn/avideoEPSS 0.33%via GHSA
CVE-2026-33692High· 7.5
3mo ago

AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration

AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration

▾ Twilightwwbn · wwbn/avideoEPSS 0.45%via GHSA
CVE-2025-67303High· 7.5PoC
3mo ago

ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)

ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)

▾ Midnightcomfyui-manager · comfyui-managerEPSS 1.4%via GHSA
CVE-2026-33731Medium· 6.5
3mo ago

AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data

AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data

▾ Sunlitwwbn · wwbn/avideoEPSS 0.21%via GHSA
CVE-2026-41579Medium· 3.3
3mo ago

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

▾ Sunlitopencontainers · github.com/opencontainers/runcEPSS 0.17%via GHSA
CVE-2026-44179Critical· 9.9
3mo ago

xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro

xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro

▾ Midnightxwiki · com.xwiki.pro:xwiki-pro-macrosvia GHSA
CVE-2026-44583Medium· 5.3
3mo ago

Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module

Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module

▾ Sunlitpaymenter · paymenter/paymenterEPSS 0.41%via GHSA
CVE-2026-44584Medium· 4.3
3mo ago

Paymenter doesn't reset email verification status after email change

Paymenter doesn't reset email verification status after email change

▾ Sunlitpaymenter · paymenter/paymenterEPSS 0.16%via GHSA
CVE-2026-44585Medium· 5.4
3mo ago

Paymenter has broken object level authorization via service reference manipulation on ticket creation

Paymenter has broken object level authorization via service reference manipulation on ticket creation

▾ Sunlitpaymenter · paymenter/paymenterEPSS 0.29%via GHSA
CVE-2026-44795High· 8.5
3mo ago

Spinnaker has uon-safe yaml deserialization, allowing RCE when using specific types

Spinnaker has uon-safe yaml deserialization, allowing RCE when using specific types

▾ Twilightspinnaker · io.spinnaker.rosco:rosco-coreEPSS 1.0%via GHSA
CVE-2026-46606High· 7.8
3mo ago

Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py

Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py

▾ Twilightglances · glancesEPSS 0.21%via GHSA
CVEs tagged “ghsa” — page 100 · VulnSea