VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3812 CVEsRSS

CVE-2026-54629High· 7.5
2w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, a…

▾ Twilightjulien040 · anyqueryEPSS 0.97%via NVD
CVE-2026-50157Medium· 6.5
2w ago

Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs

Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bear…

▾ Sunlitauth0 · symfonyEPSS 0.51%via NVD
CVE-2026-50006Critical· 9.1PoC
2w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to SQLite without restricting ATTACH DATABASE filesystem targets. A remote attacke…

▾ Abyssaljulien040 · anyqueryEPSS 0.97%via NVD
CVE-2026-47253High· 7.3PoC
2w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar function in namespace/other_functions.go passes the caller-controlled plugin parameter through path.Join to os.RemoveAll wi…

▾ Midnightjulien040 · anyqueryEPSS 0.44%via NVD
CVE-2026-47701High· 7.7
2w ago

The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector

The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator TargetAllocator instances with targetAllocator.prometheusCR.enabled set to true preserve a selected ServiceMonitor …

▾ Twilightopen-telemetry · opentelemetry-operatorEPSS 0.46%via NVD
CVE-2026-34151High· 8.2
2w ago

XWiki Platform is a generic wiki platform

XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended skin or web-application resource prefix w…

▾ Twilightxwiki · xwiki-platformEPSS 1.1%via NVD
CVE-2026-49250High· 8.7
2w ago

Conform, a type-safe form validation library, allows the parsing of nested objects in the form of object.property

Conform, a type-safe form validation library, allows the parsing of nested objects in the form of object.property. From 1.8.0 until 1.19.4, the parseSubmission future API in packages/conform-dom/formdata.ts repeatedly scans FormData or U…

▾ Twilightedmundhung · conformEPSS 0.51%via NVD
CVE-2026-44162Low· 2.7
2w ago

fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd

fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd. From 0.7.0 to 1.8.4, the in_s3 input plugin reads the entire decompressed payload of gzip, lzma2, and lzop objects into memory without enforcing a decompression_size_l…

▾ Sunlitfluent · fluent-plugin-s3EPSS 0.48%via NVD
CVE-2026-55832Medium· 6.1PoC
2w ago

Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit

Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2, the tract-onnx crate passes the attacker-controlled external_data location from an ONNX model through onnx/src/tens…

▾ Twilightsonos · tractEPSS 0.19%via NVD
CVE-2026-55091High· 7.5
2w ago

flat-to-nested converts a hierarchy from a flat representation to a nested representation

flat-to-nested converts a hierarchy from a flat representation to a nested representation. Prior to 1.1.2, FlatToNested.prototype.convert in index.js uses attacker-influenced id and parent record fields directly as keys in the plain temp…

▾ Twilightjoaonuno · flat-to-nested-jsEPSS 0.50%via NVD
CVE-2026-55795Medium· 6.9
2w ago

Craft Commerce is an ecommerce platform for Craft CMS

Craft Commerce is an ecommerce platform for Craft CMS. From 4.0.0 until 4.11.2 and 5.6.5, CartController in src/controllers/CartController.php activates its RateLimiter only when the number POST or GET parameter is supplied. An unauthent…

▾ Sunlitcraftcms · commerceEPSS 0.51%via NVD
CVE-2026-55837Medium· 6.8PoC
2w ago

dbt-mcp is a Model Context Protocol server for interacting with dbt

dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_mcp/oauth/fastapi_app.py exposes GET /dbt_platform_context without authentication or Host validation after a user com…

▾ Twilightdbt-labs · dbt-mcpEPSS 0.27%via NVD
CVE-2026-55846Medium· 6.2PoC
2w ago

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP server started by allure serve and allure open uses URI.getPath() in Commands.setUpServer() in allure-commandline/src/ma…

▾ Twilightallure-framework · allure2EPSS 0.18%via NVD
CVE-2026-55847Medium· 6.1
2w ago

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js helper at allure-generator/src/main/javascript/helpers/ansi.js passes attacker-influenced statusMessage and statusTra…

▾ Sunlitallure-framework · allure2EPSS 0.34%via NVD
CVE-2026-55866Low· 3.7
2w ago

SpiceDB is an open source database system for creating and managing security-critical application permissions

SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34.0 until 1.54.0, SpiceDB can return PERMISSIONSHIP_HAS_PERMISSION instead of PERMISSIONSHIP_CONDITIONAL_PERMISSION or…

▾ Sunlitauthzed · spicedbEPSS 0.34%via NVD
CVE-2026-47256Medium· 5.3PoC
2w ago

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. Prior to 0.154.0, the Sentry exporter r…

▾ Twilightopen-telemetry · opentelemetry-collector-contribEPSS 0.44%via NVD
CVE-2026-55093Medium· 6.1PoC
2w ago

Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit

Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1, tract-nnef uses unchecked usize multiplication in nnef/src/tensors.rs read_tensor for attacker-controlled tensor di…

▾ Twilightsonos · tractEPSS 0.18%via NVD
CVE-2026-11748Medium
2w ago

Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion

Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion

▾ Sunlitlinecorp · com.linecorp.centraldogma:centraldogma-server-auth-shiroEPSS 0.62%via GHSA
CVE-2026-59149Medium· 6.5
2w ago

@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)

@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)

▾ Sunlitmockoon · @mockoon/commons-serverEPSS 0.48%via GHSA
CVE-2026-56828High· 8.8
2w ago

Shopper: privilege escalation via improper Livewire admin component authorization

Shopper: privilege escalation via improper Livewire admin component authorization

▾ Twilightshopper · shopper/frameworkvia GHSA
CVE-2026-56826Medium· 5.4
2w ago

Shopping privilege escalation through missing authorization in Settings components

Shopping privilege escalation through missing authorization in Settings components

▾ Sunlitshopper · shopper/frameworkvia GHSA
CVE-2026-56665Medium· 4.2
2w ago

ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider

ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider

▾ Sunlitzitadel · github.com/zitadel/zitadelEPSS 0.27%via OSV
CVE-2026-59151Critical· 9.6
2w ago

Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover

Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover

▾ Midnightprowler-cloud · prowler-cloudEPSS 0.53%via OSV
CVE-2026-50013High· 7.5
2w ago

Hoverfly is an open source API simulation tool

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy…

▾ TwilightSpectoLabs · hoverflyEPSS 0.47%via NVD
CVE-2026-50018Medium· 6.5PoC
2w ago

Hoverfly is an open source API simulation tool

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable or intentionally slow (accepts TCP con…

▾ TwilightSpectoLabs · hoverflyEPSS 0.54%via NVD
CVE-2026-49992Medium· 6.3
2w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exp…

▾ Sunlitkimai · kimaiEPSS 0.22%via NVD
CVE-2026-54174High· 8.3
2w ago

melange allows users to build apk packages using declarative pipelines

melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but…

▾ Twilightchainguard-dev · melangeEPSS 0.15%via NVD
CVE-2026-54072Critical· 9.3PoC
2w ago

Authorizer is an open-source, self-hostable authentication and authorization server

Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` …

▾ Abyssalauthorizerdev · authorizerEPSS 0.46%via NVD
CVE-2026-49865Medium· 5.3PoC
2w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown content that is lat…

▾ Twilightkimai · kimaiEPSS 0.35%via NVD
CVE-2026-49463Medium· 6.5
2w ago

NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:documenten-api` package through version 3.0.0 and the `n…

▾ Sunlitnl-portal · nl.nl-portal:besluitenEPSS 0.34%via CVEORG
CVEs tagged “ghsa” — page 18 · VulnSea