VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3812 CVEsRSS

CVE-2026-55621High· 7.7
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of …

▾ Twilightlxc · github.com/lxc/incus/v7EPSS 0.34%via NVD
CVE-2026-55622High· 7.7
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an in…

▾ Twilightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.34%via NVD
CVE-2026-49114High· 7.1
1mo ago

In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check

In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check. …

▾ Twilightlinuxfoundation · onnxEPSS 0.16%via NVD
CVE-2026-76904Critical· 9.8PoC
1mo ago

GeoTools is an open source Java library that provides tools for geospatial data

GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataS…

▾ Abyssalgeotools · org.geotools.jdbc:gt-jdbc-postgisEPSS 2.4%via NVD
CVE-2026-61824High· 8.2
1mo ago

Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors

Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors

▾ Twilightdefuddle · defuddleEPSS 0.41%via GHSA
CVE-2026-63421High· 7.5
1mo ago

Keystone is a content management system for Node.js

Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core/queries/resolvers.ts compares the signed take argument directly with graphql.maxTake, allowing a remote unauthentica…

▾ Twilightkeystone-6 · @keystone-6/coreEPSS 0.67%via NVD
CVE-2026-64679High· 8.1
1mo ago

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not consistently validate user-controlled workspace values supplied through accepted reposi…

▾ Twilightrunatlantis · github.com/runatlantis/atlantisEPSS 0.80%via NVD
CVE-2026-76905High· 7.5⚖ disputed
1mo ago

kin-openapi is a Go project for handling OpenAPI files

kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openapi3filter/validation_error_encoder.go dereferences e.Parameter.In without checking whether e.Parameter is nil. A …

▾ TwilightRed Hat · Red Hat Edge Manager 1EPSS 0.61%via NVD
CVE-2026-59989Critical
1mo ago

Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)

Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)

▾ Midnightphalcon · phalcon/cphalconEPSS 0.54%via GHSA
CVE-2026-61539Critical· 10.0
1mo ago

Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

▾ Midnightxinference · xinferenceEPSS 1.2%via OSV
CVE-2026-77354High· 7.5
1mo ago

kin-openapi is a Go project for handling OpenAPI files

kin-openapi is a Go project for handling OpenAPI files. From 0.124.0 until 0.142.0, openapi3filter.sliceMapToSlice in openapi3filter/req_resp_decoder.go converts attacker-controlled sparse indexes from a deepObject query parameter into a…

▾ Twilightgetkin · github.com/getkin/kin-openapiEPSS 0.52%via NVD
CVE-2026-77413Critical· 9.8
1mo ago

JSONata is a JSON query and transformation language

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to access inherited prototype members. An…

▾ Midnightjsonata · jsonataEPSS 0.72%via NVD
CVE-2026-63135High· 8.2
1mo ago

YOURLS is a self-hosted, customizable URL shortener written in PHP

YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS stores the HTTP Referer header through yourls_get_referrer(), yourls_sanitize_url_safe(), and yourls_log_redirect(), then aggregates the …

▾ Twilightyourls · yourls/yourlsEPSS 0.43%via NVD
CVE-2026-68508High· 7.8
1mo ago

Hydra is a framework for elegantly configuring complex applications

Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.4, hydra.utils.instantiate() resolves and calls Python objects selected by configuration through _resolve_target() in hydra/_internal/instantiate/_instanti…

▾ Twilighthydra-core · hydra-coreEPSS 0.46%via NVD
CVE-2026-77414Critical· 9.8
1mo ago

JSONata is a JSON query and transformation language

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty check. Crafted expressions could use $hasOwnProperty, $spread, $string, protot…

▾ Midnightjsonata · jsonataEPSS 0.57%via NVD
CVE-2026-77415Critical· 9.8
1mo ago

JSONata is a JSON query and transformation language

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to execute arbitrary code. The chain could overwrite $clone to mutate objects thro…

▾ Midnightjsonata · jsonataEPSS 0.89%via NVD
CVE-2026-63462High· 7.5
1mo ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation error path in src/lib/error/bad-data-error.ts passes a raw request value from lodash.get to JSON.stringify in genericE…

▾ Twilightunleash-server · unleash-serverEPSS 0.70%via NVD
CVE-2026-63004Medium· 5.5
1mo ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon and integration subsystem passes the operator-controlled parameters.url value from src/lib/addons/webhook.ts and the Slack, Microsoft Team…

▾ Sunlitunleash-server · unleash-serverEPSS 0.39%via NVD
CVE-2026-63466Medium· 4.1
1mo ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, FeatureEventFormatterMd.format in src/lib/addons/feature-event-formatter-md.ts assigns Mustache.escape to an identity function before rendering action and path templa…

▾ Sunlitunleash-server · unleash-serverEPSS 0.32%via NVD
GHSA-8hgv-xc77-jmcrMedium
1mo ago

Grav: Page editors can inject arbitrary script into rendered pages via the Twig sandbox's assets.addJs/addCss allowlist, escalating to super-admin

Grav: Page editors can inject arbitrary script into rendered pages via the Twig sandbox's assets.addJs/addCss allowlist, escalating to super-admin

▾ Sunlitgetgrav · getgrav/gravvia GHSA
CVE-2026-45099Medium
1mo ago

Terragrunt is a flexible orchestration tool that allows Infrastructure as Code written in OpenTofu or Terraform to scale

Terragrunt is a flexible orchestration tool that allows Infrastructure as Code written in OpenTofu or Terraform to scale. Prior to 1.0.4, Terragrunt trusts paths decoded from a downloaded module's .terragrunt-module-manifest during fileM…

▾ Sunlitgruntwork-io · github.com/gruntwork-io/terragruntEPSS 0.54%via NVD
CVE-2026-54457High· 7.7
1mo ago

TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation

TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied…

▾ Twilighttensorzero · tensorzeroEPSS 0.40%via NVD
CVE-2026-53572Medium· 5.9
1mo ago

KEDA is a Kubernetes-based Event Driven Autoscaling component

KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgresql_scaler.go constructs libpq-style connection strings from tenant-controlled host, port, userName, dbName, sslmode, and password values,…

▾ Sunlitkedacore · github.com/kedacore/keda/v2EPSS 0.39%via NVD
CVE-2026-53530High
1mo ago

RaTeX is a KaTeX-compatible math rendering engine written in Rust

RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, the public parser entrypoint `ratex_parser::parse(&str)` panics on the 9-byte input `\verbéxé` (i.e. `\verb` followed by the non-ASCII delimiter …

▾ Twilightratex-parser · ratex-parserEPSS 0.43%via NVD
CVE-2026-53531Medium
1mo ago

RaTeX is a KaTeX-compatible math rendering engine written in Rust

RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, RaTeX’s recursive-descent parser recurses one (or more) native stack frame per nesting level at `{`, `\left`, `\sqrt{`, `^{`, etc, with no maximu…

▾ Sunlitratex-parser · ratex-parserEPSS 0.43%via NVD
CVE-2026-53487Medium· 4.3
1mo ago

Kite is a Kubernetes dashboard

Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated Kite users with any role can request `/api/v1/overview` for a cluster that their roles do not permit by selecting that cluster with `x-cluster-name`. The overview rou…

▾ Sunlitzxh326 · github.com/zxh326/kiteEPSS 0.27%via NVD
CVE-2026-53509Medium· 5.7
1mo ago

CKAN MCP Server is a tool for querying CKAN open data portals

CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a base_url parameter had the risk of making HTTP requests to a…

▾ Sunlitaborruso · @aborruso/ckan-mcp-serverEPSS 0.38%via NVD
CVE-2026-47735High
1mo ago

Arc is an open, SQL-native time-series database for telemetry

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc's user-SQL validator (`internal/api/query.go:ValidateSQLRequest`) blocked only `read_parquet(` and `arc_partition_agg(` via regex denylist. The …

▾ Twilightbasekick-labs · github.com/basekick-labs/arcEPSS 0.43%via NVD
CVE-2026-47753Medium
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateInstanceFromBackup` in `internal/server/storage/backend.go` contains a nil-pointer dereference that an authenticated user with permission …

▾ Sunlitlxc · github.com/lxc/incus/v7EPSS 0.15%via NVD
CVE-2026-48050High· 8.2
1mo ago

Arc is an open, SQL-native time-series database for telemetry

Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof` handlers at `/debug/pprof/*` via `app.Use(pprof.New())` in `internal/api/server.go`, and `/debug/pprof` is added to `…

▾ TwilightRed Hat · Red Hat Edge Manager 1EPSS 0.64%via NVD
CVEs tagged “ghsa” — page 35 · VulnSea