VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3812 CVEsRSS

CVE-2026-55226Medium· 5.4
1w ago

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, deploying only the Topic Operator or only the User Operator through the Kafka custom res…

▾ Sunlitstrimzi · strimzi-kafka-operatorEPSS 0.25%via NVD
CVE-2026-55887High· 8.7
1w ago

MCP Gateway allows easy and secure running and deployment of MCP servers

MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YAML-unmarshalled the attacker-controlled io.docker.server.metadata OCI image label into the broad catalog.Server stru…

▾ Twilightdocker · mcp-gatewayEPSS 0.22%via NVD
CVE-2026-55617Medium· 6.9
1w ago

Hydro is a next-generation high-performance online judge platform

Hydro is a next-generation high-performance online judge platform. From 4.10.4 until 5.0.2, the session recreation logic in packages/hydrooj/src/service/layers/base.ts creates a replacement session token without deleting the previous tok…

▾ Sunlithydro-dev · HydroEPSS 0.47%via NVD
CVE-2026-41573High· 7.1
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() passes the _queryId parameter from /json/{realm}/users to CrestQuery with escapeQueryId disabled, bypassing protectio…

▾ TwilightOpenIdentityPlatform · OpenAMEPSS 0.50%via NVD
CVE-2026-44202Medium· 5.3
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbitrary notification URL without requiring an administrativ…

▾ SunlitOpenIdentityPlatform · OpenAMEPSS 0.41%via NVD
CVE-2026-44203High· 8.3
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect authorization endpoint does not sufficiently encode user-supplied parameters before FormPostResponse.ftl and checkSession…

▾ TwilightOpenIdentityPlatform · OpenAMEPSS 0.59%via NVD
CVE-2026-44778Low· 2.9⚖ disputed
1w ago

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.28.0 until 0.53.1, the USDT note parser in pkg/uprobetracer/usdt.go can allow an unprivi…

▾ Sunlitinspektor-gadget · inspektor-gadgetEPSS 0.63%via NVD
CVE-2026-44793High· 7.0
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non-default clustered configuration inconsistently encode user-supplied parameters rendered into HTML in the SAML2 clust…

▾ TwilightOpenIdentityPlatform · OpenAMEPSS 0.59%via NVD
CVE-2026-46488Critical· 9.1PoC
1w ago

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, motionEye accepts the client-controlled meye_username and meye_password_hash c…

▾ Abyssalmotioneye-project · motioneyeEPSS 0.46%via NVD
CVE-2026-46495Critical· 9.2
1w ago

OpenDJ is an LDAPv3 compliant directory service

OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/java/org/opends/server/protocols/jmx/RmiConnector.java processes attacker-controlled credential objects before authen…

▾ MidnightOpenIdentityPlatform · OpenDJEPSS 1.1%via NVD
CVE-2026-45048High· 8.5
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not enforce ownership or privilege checks when a low-privileged authenticated user queries s…

▾ TwilightOpenIdentityPlatform · OpenAMEPSS 0.43%via NVD
CVE-2026-55863Medium· 5.3PoC
1w ago

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, the ActionHandler.post() method in motioneye/handlers/action.py lacks the Base…

▾ Twilightmotioneye-project · motioneyeEPSS 0.50%via NVD
CVE-2026-44163Medium· 5.3
1w ago

fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data

fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to 0.5.3, the in_opentelemetry HTTP input read the entire incoming request body and decompressed payloads into memory with…

▾ Sunlitfluent-plugins-nursery · fluent-plugin-opentelemetryEPSS 0.42%via NVD
CVE-2026-46619Critical· 9.3
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the request-supplied MSISDN value into an LDAP search filter without escaping, while the…

▾ MidnightOpenIdentityPlatform · OpenAMEPSS 0.99%via NVD
CVE-2026-46623High· 7.4
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and inetUserStatus, rewriting the…

▾ TwilightOpenIdentityPlatform · OpenAMEPSS 0.67%via NVD
CVE-2026-48785Medium· 4.8
1w ago

Apptainer is an open source container platform

Apptainer is an open source container platform. Prior to version 1.5.1, Image.AuthorizedPath applies plain string-prefix matching to the limit container paths directive in apptainer.conf, so an allowed path such as /data/safe also author…

▾ Sunlitapptainer · apptainerEPSS 0.15%via NVD
CVE-2026-45051Critical· 9.2
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators without an ObjectInp…

▾ MidnightOpenIdentityPlatform · OpenAMEPSS 0.69%via NVD
CVE-2026-45052Critical· 9.3
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote requests to write persistent entries through SOAPReceiver and DiscoveryService into …

▾ MidnightOpenIdentityPlatform · OpenAMEPSS 0.77%via NVD
CVE-2026-45794High· 7.7
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS callback handled by SnsMessageResource falls back to a CTS predicate blob after a messageId expires from the in-memory…

▾ TwilightOpenIdentityPlatform · OpenAMEPSS 0.63%via NVD
CVE-2026-46498High· 7.6
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied token identifiers from the shared Core Token Store (CTS) without an OAuth-only namespace, and OAuthAdapter accepts a…

▾ TwilightOpenIdentityPlatform · OpenAMEPSS 0.41%via NVD
CVE-2026-48722Medium· 5.5
1w ago

Nextflow is a DSL for data-driven computational pipelines

Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth login writes Seqera Platform OIDC bearer tokens to ${NXF_HOME:-~/.nextflow}/seqera-auth.config through AuthCommandImpl.…

▾ Sunlitnextflow-io · nextflowEPSS 0.14%via NVD
CVE-2026-55374Medium· 4.8
1w ago

canto-saas-api is a PHP library for interacting with the Canto SaaS API

canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, Request::buildRequestUrl() joins values returned by Request::getPathVariables() without encoding individual path segments, including the sch…

▾ Sunlitjleehr · canto-saas-apiEPSS 0.36%via NVD
CVE-2026-55375Medium· 5.3
1w ago

canto-saas-api is a PHP library for interacting with the Canto SaaS API

canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, OAuth2Request::getQueryParams() places app_id, app_secret, refresh_token, and code in the URL query string of token POST requests, allowing …

▾ Sunlitjleehr · canto-saas-apiEPSS 0.38%via NVD
CVE-2026-55690High· 7.5
1w ago

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedServiceFactory::newFromName in includes…

▾ TwilightStarCitizenWiki · mediawiki-extensions-EmbedVideoEPSS 0.49%via NVD
CVE-2026-55691High· 8.6PoC
1w ago

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedHtmlFormatter::toHtml in includes/Embed…

▾ MidnightStarCitizenWiki · mediawiki-extensions-EmbedVideoEPSS 0.48%via NVD
CVE-2026-55828Medium· 6.0
1w ago

qbee transport is a remote access transport protocol implementation

qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses strictly lexical path validation that does not account for on-disk symlinks created earlier in the extraction process. A c…

▾ Sunlitqbee-io · transportEPSS 0.38%via NVD
CVE-2026-55650Medium· 4.4PoC
1w ago

Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite

Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitized Text Widget content through dangero…

▾ Twilightouterbase · studioEPSS 0.19%via NVD
CVE-2026-55692High· 7.5PoC
1w ago

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with the default $wgEmbedVideoRequireConsent…

▾ MidnightStarCitizenWiki · mediawiki-extensions-EmbedVideoEPSS 0.49%via NVD
CVE-2026-55770Medium· 6.8PoC
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/lda…

▾ Twilightopenbao · openbaoEPSS 0.53%via NVD
CVE-2026-55774Low· 2.1
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/leases/revoke/:lease_id in one namespace could revoke a lease in another namespace when the foreign lease_id was known…

▾ Sunlitopenbao · openbaoEPSS 0.56%via NVD
CVEs tagged “ghsa” — page 15 · VulnSea