VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3812 CVEsRSS

CVE-2026-55406Medium
1mo ago

Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref

Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref

▾ Sunlitbuffa · buffaEPSS 0.19%via GHSA
CVE-2026-55407Medium
1mo ago

Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation

Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation

▾ Sunlitbuffa · buffaEPSS 0.76%via GHSA
CVE-2026-55673High
1mo ago

PowSyBl (Power System Blocks) is a framework to build power system oriented software

PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to 7.2.2, UnixLocalCommandExecutor and WindowsLocalCommandExecutor concatenate command arguments and environment variables into strings interpret…

▾ Twilightpowsybl · com.powsybl:powsybl-computation-localEPSS 0.60%via NVD
CVE-2026-55248Critical· 9.1
1mo ago

plone.app.portlets vulnerable to denial of service via RSS feed portlet

plone.app.portlets vulnerable to denial of service via RSS feed portlet

▾ Midnightplone-app-portlets · plone-app-portletsEPSS 0.44%via OSV
CVE-2026-55520High
1mo ago

Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching

Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching

▾ Twilightprotego · protegoEPSS 0.51%via OSV
CVE-2026-55227Medium· 4.3
1mo ago

Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

▾ Sunlitweblate · weblateEPSS 0.32%via OSV
CVE-2026-55228High· 8.1
1mo ago

Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

▾ Twilightweblate · weblateEPSS 0.45%via OSV
CVE-2026-55247Critical· 9.1
1mo ago

plone.app.event vulnerable to denial of service via iCalendar import

plone.app.event vulnerable to denial of service via iCalendar import

▾ Midnightplone-app-event · plone-app-eventEPSS 0.44%via OSV
CVE-2026-55215High· 7.5
1mo ago

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versions 3.3.3, 3.4.6, and 3.5.3, when ssl is enabled without a pinned CA or server certificate, MariaDB Connector/No…

▾ Twilightmariadb · mariadbEPSS 0.57%via NVD
CVE-2026-55207High· 8.8
1mo ago

Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass

Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass

▾ Twilightpimcore · pimcore/studio-backend-bundleEPSS 0.67%via GHSA
CVE-2026-55208High· 7.7
1mo ago

Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes

Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes

▾ Twilightpimcore · pimcore/studio-backend-bundleEPSS 0.41%via GHSA
CVE-2026-55220Critical
1mo ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, Pimcore\Model\DataObject\ClassDefinition\Data\Hotspotimage::getDataFromResource() in models/DataObject/ClassDefinition/Data/Hotspot…

▾ Midnightpimcore · pimcore/pimcoreEPSS 0.68%via NVD
CVE-2026-55634Critical· 9.9
1mo ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObjec…

▾ Midnightpimcore · pimcore/pimcoreEPSS 0.65%via NVD
CVE-2026-55484High· 7.5
1mo ago

ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack

ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.0-20260617230736-314b6783e196, core/utils.go::sanitizeRequestPath calls splitPathQuery on a request path beginning wi…

▾ Twilightguno1928 · github.com/guno1928/alos-httpEPSS 0.49%via NVD
GHSA-73p9-6hrp-8qhrMedium
1mo ago

AIIR verification and policy gates could report success without enforcing the control (fail-open)

AIIR verification and policy gates could report success without enforcing the control (fail-open)

▾ Sunlitaiir · aiirvia GHSA
CVE-2026-55559Critical· 9.8
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templat…

▾ Midnightyamcs · org.yamcs:yamcs-coreEPSS 0.78%via NVD
CVE-2026-55565Critical· 9.9
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source c…

▾ Midnightyamcs · org.yamcs:yamcs-coreEPSS 0.65%via NVD
CVE-2026-55566Medium· 4.3
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext URL route in yamcs-web/src/main/webapp/projects/webapp/src/app/core/routes/extension.matcher.ts, extension.component…

▾ Sunlityamcs · org.yamcs:yamcs-coreEPSS 0.38%via NVD
CVE-2026-55460High· 7.1
1mo ago

Snipe-IT has an authorization bypass on bulk editing users

Snipe-IT has an authorization bypass on bulk editing users

▾ Twilightsnipe · snipe/snipe-itEPSS 0.44%via GHSA
CVE-2026-55464Medium· 5.4
1mo ago

Snipe-IT vulnerable to stored XSS via Markdown custom field

Snipe-IT vulnerable to stored XSS via Markdown custom field

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.29%via GHSA
CVE-2026-55472Medium· 4.3
1mo ago

Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation

Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.33%via GHSA
CVE-2026-55476Medium
1mo ago

Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter

Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.34%via GHSA
CVE-2026-55516High· 7.7
1mo ago

Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update

Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update

▾ Twilightsnipe · snipe/snipe-itEPSS 0.38%via GHSA
CVE-2026-55425Medium· 5.0
1mo ago

Graylog is a free and open log management platform

Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity titles endpoint in graylog2-server/src/main/java/org/graylog2/rest/resources/system/contentpacks/titles/EntityTitleSe…

▾ Sunlitgraylog2 · org.graylog2:graylog2-serverEPSS 0.41%via NVD
CVE-2026-55509High
1mo ago

WsgiDAV MySQL provider has a blind SQL injection

WsgiDAV MySQL provider has a blind SQL injection

▾ Twilightwsgidav · wsgidavEPSS 0.54%via OSV
CVE-2026-55485High· 8.8
1mo ago

piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.

piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.

▾ Twilightpiccolo-admin · piccolo-adminEPSS 0.56%via OSV
CVE-2026-54754Critical· 9.6
1mo ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading asset.Royalties.MarketPer…

▾ Midnightklever-io · github.com/klever-io/klever-goEPSS 0.43%via NVD
CVE-2026-54755Critical· 9.6
1mo ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go a…

▾ Midnightklever-io · github.com/klever-io/klever-goEPSS 0.56%via NVD
CVE-2026-55569Medium· 6.6
1mo ago

aqua is a declarative command-line version manager written in Go

aqua is a declarative command-line version manager written in Go. Prior to 2.60.1, pkg/unarchive/archives.go in the handler.HandleFile method calls os.Symlink with archives.FileInfo.LinkTarget without verifying that the target remains un…

▾ Sunlitaquaproj · github.com/aquaproj/aqua/v2EPSS 0.18%via NVD
CVE-2026-55834Medium· 4.3
1mo ago

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services. From 2.6.0 until 2.9.0, frontend/src/routes/authorize/+page.ts reads the redirect_uri query parameter and frontend/src/routes/authorize/+pag…

▾ Sunlitpocket-id · github.com/pocket-id/pocket-id/backendEPSS 0.37%via NVD
CVEs tagged “ghsa” — page 28 · VulnSea