VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-46607High· 7.8
3mo ago

Glances has Insecure Pickle Deserialization in its Version Cache that Leads to Arbitrary Code Execution

Glances has Insecure Pickle Deserialization in its Version Cache that Leads to Arbitrary Code Execution

▾ Twilightglances · glancesEPSS 0.36%via GHSA
CVE-2026-46608High· 7.4
3mo ago

Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)

Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)

▾ Twilightglances · glancesEPSS 0.40%via GHSA
CVE-2026-46611Medium· 5.3
3mo ago

Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack

Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack

▾ Sunlitglances · glancesEPSS 0.17%via GHSA
CVE-2026-46672Medium· 4.6
3mo ago

@actual-app/cli `--format csv` Output Vulnerable to CSV Formula Injection via Custom `escapeCsv` Helper

@actual-app/cli `--format csv` Output Vulnerable to CSV Formula Injection via Custom `escapeCsv` Helper

▾ Sunlitactual-app · @actual-app/cliEPSS 0.19%via GHSA
CVE-2026-46700Medium· 4.3
3mo ago

@actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets

@actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets

▾ Sunlitactual-app · @actual-app/sync-serverEPSS 0.34%via GHSA
CVE-2026-47267Medium
3mo ago

Gogs has SSRF in webhook deliveries

Gogs has SSRF in webhook deliveries

▾ Sunlitgogs · gogs.io/gogsEPSS 0.42%via GHSA
GHSA-74p7-6h78-gw8pHigh
3mo ago

skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery

skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery

▾ Twilightskillctl · skillctlvia GHSA
CVE-2026-48153High· 8.5
3mo ago

Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata

Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata

▾ Twilightbudibase · @budibase/serverEPSS 0.29%via GHSA
GHSA-ghmh-jhmj-wcmfMedium
3mo ago

nebula-mesh's stores enrollment tokens unhashed in SQLite

nebula-mesh's stores enrollment tokens unhashed in SQLite

▾ Sunlitjuev · github.com/juev/nebula-meshvia GHSA
GHSA-hvqh-jw65-wcpqMedium· 5.4
3mo ago

devbridge-autocomplete has XSS in its default formatters: formatGroup and formatResult fail to escape HTML in untrusted inputs

devbridge-autocomplete has XSS in its default formatters: formatGroup and formatResult fail to escape HTML in untrusted inputs

▾ Sunlitdevbridge-autocomplete · devbridge-autocompletevia GHSA
CVE-2026-48487Medium· 6.5
3mo ago

zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet

zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet

▾ Sunlitzeroconf · zeroconfEPSS 0.47%via GHSA
CVE-2026-50132High· 7.3
3mo ago

Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF

Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF

▾ Twilightbudibase · @budibase/serverEPSS 0.19%via GHSA
CVE-2026-50136High· 7.4
3mo ago

Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentials

Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentials

▾ Twilightbudibase · @budibase/serverEPSS 0.29%via GHSA
CVE-2026-50137High
3mo ago

Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials

Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials

▾ Twilightbudibase · @budibase/serverEPSS 0.41%via GHSA
CVE-2026-49229High· 8.3
3mo ago

@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens

@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens

▾ Twilightactual-app · @actual-app/sync-serverEPSS 0.44%via GHSA
CVE-2026-54351High· 8.2
3mo ago

Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override

Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override

▾ Twilightbudibase · @budibase/serverEPSS 0.46%via GHSA
CVE-2026-54352Critical· 9.6
3mo ago

Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload

Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload

▾ Midnightbudibase · @budibase/serverEPSS 0.49%via GHSA
CVE-2026-54353High· 8.5
3mo ago

@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation

@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation

▾ Twilightbudibase · @budibase/backend-coreEPSS 0.21%via GHSA
CVE-2026-50179Medium· 4.2
3mo ago

@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields

@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields

▾ Sunlitactual-app · @actual-app/webEPSS 0.29%via GHSA
CVE-2026-52796Low· 3.5
3mo ago

Gogs has DoS in rendering issue index pattern

Gogs has DoS in rendering issue index pattern

▾ Sunlitgogs · gogs.io/gogsEPSS 0.28%via GHSA
CVE-2026-52798High· 8.9
3mo ago

Gogs has Stored XSS in `.ipynb` Preview

Gogs has Stored XSS in `.ipynb` Preview

▾ Twilightgogs · gogs.io/gogsEPSS 0.43%via GHSA
CVE-2026-52799High· 7.5
3mo ago

Gogs Missing Authorization in Attachment Download

Gogs Missing Authorization in Attachment Download

▾ Twilightgogs · gogs.io/gogsEPSS 0.42%via GHSA
CVE-2026-12799Medium· 4.3
3mo ago

BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure

BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure

▾ Sunlitlitellm · litellmEPSS 0.43%via OSV
GHSA-24r3-p3x6-cqvxCritical· 9.6
3mo ago

Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
CVE-2026-56265Critical· 9.8PoC
3mo ago

Crawl4AI: authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server

Crawl4AI: authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server

▾ Abyssalcrawl4ai · crawl4aiEPSS 2.6%via GHSA
CVE-2026-12796Medium· 6.3
3mo ago

BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens

BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens

▾ Sunlitlitellm · litellmEPSS 0.57%via OSV
CVE-2026-12798Medium· 6.3
3mo ago

BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader

BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader

▾ Sunlitlitellm · litellmEPSS 0.40%via OSV
CVE-2026-12797Medium· 6.3
3mo ago

BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints

BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints

▾ Sunlitlitellm · litellmEPSS 0.40%via OSV
GHSA-fh2f-24rh-r2vqHigh
3mo ago

Duplicate Advisory: Picklescan missing detection when calling built-in python library function timeit.timeit()

Duplicate Advisory: Picklescan missing detection when calling built-in python library function timeit.timeit()

▾ Twilightpicklescan · picklescanvia GHSA
GHSA-fcqg-3mwf-cfcfHigh· 8.1
3mo ago

Duplicate Advisory: Picklescan is missing detection when calling built-in Python cProfile.runctx

Duplicate Advisory: Picklescan is missing detection when calling built-in Python cProfile.runctx

▾ Twilightpicklescan · picklescanvia GHSA
CVEs tagged “ghsa” — page 101 · VulnSea