VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3808 CVEsRSS

CVE-2026-61814High· 7.5
4d ago

Jawn is an open source JSON parser

Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a single JSON token is delivered across many small chunks because each absorb call rescans the incomplete token from the start. A remo…

▾ Twilighttypelevel · jawnEPSS 0.57%via NVD
CVE-2026-61695High· 7.5
4d ago

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0.0-alpha04, Wire's Swift runtime ProtoReader.skipGroup(expectedEndTag:unknownFieldsWriter:) accepts a negative length for a LENGTH_DELIMI…

▾ Twilightsquare · github.com/square/wireEPSS 0.58%via NVD
CVE-2026-59990High· 7.5
4d ago

Jawn is an open source JSON parser

Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nesting without a depth limit, allowing a remote attacker who can submit untrusted JSON to grow parser contexts until th…

▾ Twilighttypelevel · jawnEPSS 0.62%via NVD
CVE-2026-77420Medium· 5.5
4d ago

JLine is a Java library for handling console input

JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, DefaultHistory.matchPatterns(String patterns, String line) in reader/src/main/java/org/jline/reader/impl/history/DefaultHistory.java converts the HIS…

▾ Sunlitjline · jline3EPSS 0.12%via NVD
CVE-2026-56675High· 8.3
4d ago

9router /v1 APIs has unauthenticated access via reverse proxy locality collapse

9router /v1 APIs has unauthenticated access via reverse proxy locality collapse

▾ Twilight9router · 9routerEPSS 0.50%via GHSA
CVE-2026-56679High
4d ago

9router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade

9router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade

▾ Twilight9router · 9routerEPSS 0.52%via GHSA
CVE-2026-56678Medium· 6.4
4d ago

9router: Kiro region injection allows authenticated SSRF with Authorization header forwarding

9router: Kiro region injection allows authenticated SSRF with Authorization header forwarding

▾ Sunlit9router · 9routerEPSS 0.29%via GHSA
CVE-2026-56676High· 7.4
4d ago

9router: Image prefetch DNS rebinding allows SSRF to internal services

9router: Image prefetch DNS rebinding allows SSRF to internal services

▾ Twilight9router · 9routerEPSS 0.26%via GHSA
CVE-2026-77422High· 7.5PoC
4d ago

JLine is a Java library for handling console input

JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command in builtins/src/main/java/org/jline/builtins/PosixCommands.java accepts a user-controlled regular expression in grep(…

▾ Midnightjline · jline3EPSS 0.50%via NVD
CVE-2026-77421Medium· 6.5
4d ago

JLine is a Java library for handling console input

JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nano editor's regex search mode passes a user-controlled search term from doSearch(String text) in builtins/src/main/java/org/jlin…

▾ Sunlitjline · jline3EPSS 0.43%via NVD
CVE-2026-92692Medium· 6.9
4d ago

Sulu is an open-source PHP content management system based on the Symfony framework

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affected Sulu 2.6 and 3.0 release lines have a Smart Content QueryBuilder in src/Sulu/Component/Content/SmartContent/Quer…

▾ Sunlitsulu · suluEPSS 0.33%via NVD
CVE-2026-85724Critical· 9.6PoC
4d ago

Moquette is a lightweight Java MQTT broker

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOperation substitutes client ID and username values directly into rules containing %c or %u and then t…

▾ Abyssalmoquette · moquetteEPSS 0.26%via NVD
CVE-2026-92164Medium· 6.5
4d ago

Streamlink is a CLI utility which pipes video streams from various services into a video player

Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.6.0, HTTPSession mounts a FileAdapter for the file scheme and inherits redirect handling from requests.Session without rejecting …

▾ Sunlitstreamlink · streamlinkEPSS 0.27%via NVD
CVE-2026-73858Medium· 5.3PoC
4d ago

Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool

Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. From 5.0.0 through 5.10.13, submitted values from public Freeform forms can be evaluated by the isolated Twig renderer when rendered into HTML attributes.…

▾ Twilightsolspace · craft-freeformEPSS 0.43%via NVD
CVE-2026-62998Medium· 4.3PoC
4d ago

REDAXO is a PHP-based content management system

REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_list::getSortColumn() in redaxo/src/core/lib/list.php accepts the sort request parameter without checking whether setColumnSortable() registered the requested column. …

▾ Twilightredaxo · coreEPSS 0.27%via NVD
CVE-2026-63001Medium· 4.8
4d ago

REDAXO is a PHP-based content management system

REDAXO is a PHP-based content management system. Prior to 5.21.2, the mediaIsInUse() handler in redaxo/src/addons/media_manager/lib/media_manager.php inserts a Media Manager type name into raw backend warning HTML without escaping it whe…

▾ Sunlitredaxo · coreEPSS 0.18%via NVD
CVE-2026-54892High
4d ago

Plug: quadratic-time decoding of nested query/body parameters enables denial of service

Plug: quadratic-time decoding of nested query/body parameters enables denial of service

▾ Twilightplug · plugEPSS 0.95%via GHSA
CVE-2026-88974Medium· 5.4PoC
4d ago

WPGraphQL provides a GraphQL API for WordPress sites

WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post author, but does not enforce the obje…

▾ Twilightwp-graphql · wp-graphqlEPSS 0.27%via NVD
CVE-2026-63002Medium· 4.8PoC
4d ago

REDAXO is a PHP-based content management system

REDAXO is a PHP-based content management system. Prior to 5.21.2, redaxo/src/addons/mediapool/pages/sync.php inserts filenames held in $diffFiles from the media filesystem into the Mediapool Sync page without rex_escape(). An attacker wh…

▾ Twilightredaxo · coreEPSS 0.18%via NVD
CVE-2026-63000Medium· 6.4
4d ago

REDAXO is a PHP-based content management system

REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_api_install_package_update in redaxo/src/addons/install/lib/api/api_package_update.php inherits the false default from rex_api_function::requiresCsrfProtection() inste…

▾ Sunlitredaxo · coreEPSS 0.13%via NVD
CVE-2026-59167Critical· 10.0PoC
4d ago

SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies

SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler…

▾ Abyssalsuneditor · suneditorEPSS 0.39%via NVD
CVE-2026-77285Low· 2.4⚖ disputed
4d ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao Agent's exec rendering mode could write secrets from env_template to standard output when command/agent/exec/exec.go re-created the template runn…

▾ Sunlitopenbao · openbaoEPSS 0.13%via NVD
CVE-2026-63132Critical· 9.2
4d ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path in http/logical.go compared the highly privileged recovery token with ordinary string equality. A remote unauthentic…

▾ Midnightopenbao · openbaoEPSS 0.50%via NVD
CVE-2026-63131Medium· 6.0
4d ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's vault/policy/acl.go could evaluate a broader wildcard ACL grant before more-specific trailing-wildcard ACL paths with capabilities = ["deny"] f…

▾ Sunlitopenbao · openbaoEPSS 0.35%via NVD
CVE-2026-57168Critical· 9.6
4d ago

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-56120. Reason: This candidate is a duplicate of CVE-2026-56120. Notes: All CVE users should reference CVE-2026-56120 instead of this candidate.

▾ Midnightopenremote · io.openremote:openremote-managervia NVD
CVE-2026-61685High· 7.5
5d ago

ReactPress is a publishing system for React developers

ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list endpoints build TypeORM `QueryBuilder` conditions using unsanitized HTTP query parameter names as SQL column identifiers (e.g. `` `articl…

▾ Twilightfecommunity · reactpressEPSS 0.53%via NVD
CVE-2026-57576Medium· 6.5
5d ago

plone.app.dexterity is a content-type system for the Plone content management system, and plone.app.contenttypes provides Plone’s Dexterity-based content types

plone.app.dexterity is a content-type system for the Plone content management system, and plone.app.contenttypes provides Plone’s Dexterity-based content types. Plone.app.dexterity versions through 3.2.2, 4.0.0 through 4.1.2, and 5.0.0, …

▾ Sunlitplone · plone.app.dexterityEPSS 0.76%via NVD
CVE-2026-62364Low· 2.3
5d ago

wlc is a Weblate command-line client using Weblate's REST API

wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration from .weblate, .weblate.ini, or weblate.ini can select the API URL while an unscoped API token is supplied through WLC_…

▾ SunlitWeblateOrg · wlcEPSS 0.08%via NVD
CVE-2026-76910Medium· 5.3PoC
5d ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, cloneFeatureToggle and POST /api/admin/projects/:projectId/features/:featureName/clone authorize creation in the destination project but do not verify access to the s…

▾ TwilightUnleash · unleashEPSS 0.30%via NVD
CVE-2026-76909Low· 2.1
5d ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, the change-request approval email template at src/mailtemplates/requested-cr-approval/requested-cr-approval.html.mustache renders the user-controlled changeRequestTit…

▾ SunlitUnleash · unleashEPSS 0.27%via NVD
CVEs tagged “ghsa” — page 3 · VulnSea