VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3812 CVEsRSS

CVE-2026-54721High· 8.8
1mo ago

Silverstripe UserForms provides a visual form builder for the Silverstripe CMS

Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted a…

▾ Twilightsilverstripe · silverstripe/userformsEPSS 0.73%via NVD
CVE-2026-54713Low· 3.7
1mo ago

CakePHP Queue is a queue-interop compatible queueing library

CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() generates identifiers for jobs with shouldBeUnique enabled from the job class, method, and parameters, but sorting paramet…

▾ Sunlitcakephp · cakephp/queueEPSS 0.46%via NVD
CVE-2026-57171High· 7.7
1mo ago

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author comma…

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.22%via NVD
GHSA-2rrw-hpqm-36pvHigh· 7.5
1mo ago

Duplicate Advisory: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions

Duplicate Advisory: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions

▾ Twilightnltk · nltkvia GHSA
CVE-2026-60004Critical· 9.8CISA KEV0dayPoC
1mo ago

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

▾ HadalGitea · GiteaEPSS 24%via CVEORG
CVE-2026-80205High· 7.5
1mo ago

nltk: NLTK: Denial of Service via unvalidated regular expressions (CVE-2026-80205)

A flaw was found in NLTK. A remote attacker can exploit a regular expression denial of service (ReDoS) vulnerability in the `Text.findall()` and `TokenSearcher.findall()` methods. These methods accept user-supplied regular expressions with…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.65%via CSAF
CVE-2026-57170High· 7.8
1mo ago

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-par…

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.24%via NVD
GHSA-7w8c-qgxg-m7jxHigh· 7.1
1mo ago

LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates

LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates

▾ Twilightlibrenms · librenms/librenmsvia GHSA
CVE-2026-44701Low· 3.5
1mo ago

OpenSTAManager has HTML Injection in modules/utenti/edit.php

OpenSTAManager has HTML Injection in modules/utenti/edit.php

▾ Sunlitdevcode-it · devcode-it/openstamanagervia GHSA
CVE-2026-54563High· 7.1
1mo ago

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root

▾ Twilightcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.32%via GHSA
CVE-2026-54606High
1mo ago

SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies

SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 3.1.4, the SunEditor Embed plugin in src/plugins/modal/embed.js parses attacker-controlled raw embed HTML with DOMParser and proc…

▾ Twilightsuneditor · suneditorEPSS 0.58%via NVD
CVE-2026-54569Critical· 9.8
1mo ago

senaite.core Vulnerable to Eval Injection and Missing Authorization

senaite.core Vulnerable to Eval Injection and Missing Authorization

▾ Midnightsenaite-core · senaite-coreEPSS 1.2%via OSV
CVE-2026-54614Medium· 4.3
1mo ago

DebugKit provides a debugging toolbar for CakePHP applications

DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feature in src/Controller/MailPreviewController.php accepts a route-controlled previewName value in findPreview and passe…

▾ Sunlitcakephp · cakephp/debug_kitEPSS 0.54%via NVD
CVE-2026-54590Medium· 5.9
1mo ago

asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakl…

asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution

▾ Sunlitasyncssh · asyncsshEPSS 0.39%via OSV
CVE-2026-54591High· 8.1
1mo ago

asyncssh has SCP Path Traversal to Arbitrary File Write

asyncssh has SCP Path Traversal to Arbitrary File Write

▾ Twilightasyncssh · asyncsshEPSS 0.49%via OSV
CVE-2026-54556High
1mo ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, an unauthenticated HTTP/2 peer can cause an out-of-memory denial of service in the Ember backend with HTTP/2 enabled. The Hpack wrapper in ember-core/shared/s…

▾ Twilighthttp4s · org.http4s:http4s-ember-core_2.12EPSS 0.52%via NVD
CVE-2026-54553Medium· 5.4
1mo ago

Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

▾ Sunlitstarlette-admin · starlette-adminEPSS 0.45%via OSV
CVE-2026-54548Low· 3.3
1mo ago

kas Persistently Disables SSH Host Key Checking

kas Persistently Disables SSH Host Key Checking

▾ Sunlitkas · kasEPSS 0.11%via OSV
CVE-2026-54523Critical· 9.6
1mo ago

Kyverno is a policy engine designed for cloud native platform engineering teams

Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to …

▾ Midnightkyverno · github.com/kyverno/kyvernoEPSS 0.47%via NVD
CVE-2026-54550High· 7.4
1mo ago

IzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers

IzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers. In 5.2.6 and earlier, UnpackerBase.unpack() in izpack-installer/src/main/java/com/izforge/izpack/installer/unpacker/UnpackerBase.j…

▾ Twilightcodehaus · org.codehaus.izpack:izpack-installerEPSS 0.45%via NVD
CVE-2026-54511High· 8.6
1mo ago

LogTape is an unobtrusive logging library

LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStructuredDataValue() function in packages/syslog/src/syslog.ts does not neutralize C0 control characters from U+0000 thro…

▾ Twilightlogtape · @logtape/syslogEPSS 0.48%via NVD
GHSA-93qj-5q5v-3c2hCritical
1mo ago

Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)

Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)

▾ Midnightpantheon-agents · pantheon-agentsvia GHSA
GHSA-x287-5c68-36wpMedium· 5.3
1mo ago

OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses

OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses

▾ Sunlitopenwisp-ipam · openwisp-ipamvia GHSA
CVE-2026-54245High
1mo ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional access integration in Fleet Premium is vulnerable to SQL injection through a host-supplied value that is used in a dat…

▾ Twilightfleetdm · github.com/fleetdm/fleetEPSS 0.57%via NVD
CVE-2026-54256Medium· 5.4
1mo ago

Winter CMS is a content management system built on the Laravel PHP framework

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend FileUpload form widget trusted an attacker-controlled file_id POST parameter when resolving the attachment …

▾ Sunlitwinter · winter/wn-backend-moduleEPSS 0.24%via NVD
CVE-2026-63179Medium· 4.9
1mo ago

Winter CMS is a content management system built on the Laravel PHP framework

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, authenticated backend users can disclose arbitrary files readable by the PHP process by injecting @import (inline) dire…

▾ Sunlitwinter · winter/wn-backend-moduleEPSS 0.52%via NVD
CVE-2026-55182High
1mo ago

LibreNMS is a network monitoring system

LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable to command injection because the signal-cli path and the Recipient field of an alert transport entry are insufficient…

▾ Twilightlibrenms · librenms/librenmsEPSS 1.6%via NVD
CVE-2026-32639Medium· 6.8
1mo ago

Winter CMS is a content management system built on the Laravel PHP framework

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor AJAX handlers did not enforce per-template-type permission checks, allowing a backend us…

▾ Sunlitwinter · winter/wn-cms-moduleEPSS 0.46%via NVD
CVE-2026-35445High
1mo ago

Winter CMS is a content management system built on the Laravel PHP framework

Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler name submitted through the form postback _handler POST field, allowing an authenticated b…

▾ Twilightwinter · winter/wn-backend-moduleEPSS 0.44%via NVD
CVE-2026-45694Medium· 5.4
1mo ago

LibreNMS is a network monitoring system

LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cross-site scripting through the user-supplied instance and vmid GET parameters, which are reflected…

▾ Sunlitlibrenms · librenms/librenmsEPSS 0.24%via NVD
CVEs tagged “ghsa” — page 30 · VulnSea