VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3820 CVEsRSS

CVE-2026-68922Medium· 5.5
1mo ago

MobSF is a mobile application security testing tool used

MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobsf/StaticAnalyzer/views/android/icon_analysis.py uses the Android manifest android:icon value to construct paths under the scan resource d…

▾ Sunlitmobsf · mobsfEPSS 0.46%via NVD
GHSA-2mf3-mr2r-r4vfHigh· 7.5
1mo ago

@rhinostone/swig: arbitrary local file read via include/extends path traversal

@rhinostone/swig: arbitrary local file read via include/extends path traversal

▾ Twilightrhinostone · @rhinostone/swigvia GHSA
CVE-2026-55839High· 8.7
1mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link.ts allows a user with permission to create or update a Flow description to inject JavaS…

▾ Twilightkestra · io.kestra:kestraEPSS 0.43%via NVD
CVE-2026-63328Medium
1mo ago

Trivy is a security scanner

Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins without confining plugin names to that root, allowing an attacker who persuades a user to i…

▾ Sunlitaquasecurity · github.com/aquasecurity/trivyEPSS 0.19%via NVD
CVE-2026-69220High
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReade…

▾ Twilightrabbitmq · com.rabbitmq:amqp-clientEPSS 0.73%via NVD
CVE-2026-69219High· 7.5
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to accept a wire-…

▾ Twilightrabbitmq · com.rabbitmq:amqp-clientEPSS 0.73%via NVD
CVE-2026-63337High· 8.8
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.tools.jsonrpc.ProcedureDescription receives a javaReturnType value in an untrusted syst…

▾ Twilightrabbitmq · com.rabbitmq:amqp-clientEPSS 0.56%via NVD
CVE-2026-63335Medium
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly in src/main/java/com/rabbitmq/client/impl/CommandAssembler.java proces…

▾ Sunlitrabbitmq · com.rabbitmq:amqp-clientEPSS 0.52%via NVD
CVE-2026-63336Medium
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.ConnectionFactory.useSslProtocol() and ConnectionFactory.useSslProtocol(String) …

▾ Sunlitrabbitmq · com.rabbitmq:amqp-clientEPSS 0.31%via NVD
CVE-2026-61634Low· 7.5
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning path records the negotiated AMQP frame_max value, but src/main/java/com/r…

▾ Sunlitrabbitmq · com.rabbitmq:amqp-clientEPSS 0.49%via NVD
CVE-2026-70657Medium· 4.3
1mo ago

Copyparty is a portable file server

Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined with the fk or fka file-key flag can convert a valid file key into a directory key, granting read access to the conta…

▾ Sunlitcopyparty · copypartyEPSS 0.33%via NVD
CVE-2026-48798High· 7.1
1mo ago

SSH.NET is a Secure Shell (SSH) library for .NET

SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the r…

▾ TwilightSSH · SSH.NETEPSS 0.42%via NVD
CVE-2026-63632Low· 3.3
1mo ago

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/vers…

▾ Sunlitonnx · onnxEPSS 0.17%via NVD
CVE-2026-59949Medium· 6.5
1mo ago

yawkat LZ4 Java provides LZ4 compression for Java

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.n…

▾ Sunlityawk · at.yawk.lz4:lz4-javaEPSS 0.47%via NVD
CVE-2026-59940Critical· 9.8
1mo ago

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general…

▾ Midnightseroval · serovalEPSS 0.81%via NVD
CVE-2026-62684Low· 2.7
1mo ago

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, the Link storage struct is serialized directly by sharePostHandler, shareListHandl…

▾ Sunlitfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.43%via NVD
CVE-2026-54570Medium· 6.9
1mo ago

AngleSharp is a .NET library for parsing angle bracket based hyper-texts

AngleSharp is a .NET library for parsing angle bracket based hyper-texts. Prior to 1.5.0, MathAnnotationXmlElement in AngleSharp/Mathml/Dom/Internal/MathAnnotationXmlElement.cs is not treated as an HTML integration point when its encodin…

▾ SunlitAngleSharp · AngleSharpEPSS 0.33%via NVD
CVE-2026-53533Medium
1mo ago

aiosmtplib is an asynchronous SMTP client for use with asyncio

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), and SMTP.expn() send caller-supplied addresses without rejecting embedded CR or LF bytes. Data after the line break is…

▾ Sunlitaiosmtplib · aiosmtplibEPSS 0.53%via NVD
CVE-2026-47719High· 8.2
1mo ago

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Socket.IO handlers in server/runtime/index.js omit isSocketWriteAuthorized and accept attacker-contro…

▾ Twilightfuxa-server · fuxa-serverEPSS 0.59%via NVD
CVE-2026-47720Medium· 5.3
1mo ago

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString function in server/runtime/storage/tdengine/index.js doubles single quotes but does not escape …

▾ Sunlitfuxa-server · fuxa-serverEPSS 0.64%via NVD
CVE-2026-47721Medium· 6.3
1mo ago

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in server/api/scheduler/index.js do not consistently enforce authJwt.haveAdminPermission for schedule…

▾ Sunlitfuxa-server · fuxa-serverEPSS 0.43%via NVD
CVE-2026-55426High· 7.8
1mo ago

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands. From the earliest affected releases u…

▾ Twilightlinuxfabrik-lib · linuxfabrik-libEPSS 0.21%via NVD
CVE-2026-53759Low
1mo ago

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 4.2.0, db_sqlite.py created SQLite databases at predictable paths in the shared /tmp directory and followed att…

▾ Sunlitlinuxfabrik-lib · linuxfabrik-libEPSS 0.19%via NVD
CVE-2026-49452Medium· 6.5
1mo ago

WeasyPrint helps web developers to create PDF documents

WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-hint attribute values into CSS in weasyprint/css/__init__.py when presentational_hints=True. The background attribute…

▾ Sunlitweasyprint · weasyprintEPSS 0.37%via NVD
CVE-2026-52736High
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer can stall a Zebra node by racing an invalid block body against the valid canonical body for the same block header hash. ZIP-244 permits the…

▾ Twilightzebra-state · zebra-stateEPSS 0.61%via NVD
CVE-2026-52735Critical
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd rejects because the P2SH signature-operation counter undercounts redeem scripts containing a disabled opcode followed by signature opcod…

▾ Midnightzebra-script · zebra-scriptEPSS 0.51%via NVD
CVE-2026-52737Medium· 5.3
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious unauthenticated P2P peer can answer Zebra's outbound getblocks or FindBlocks request with a small two-hash inventory and then serve a syntactically valid block w…

▾ Sunlitzebra-consensus · zebra-consensusEPSS 0.26%via NVD
CVE-2026-52738Medium
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a consensus-valid block containing a long chain of transparent self-spends to one address can permanently halt Zebra nodes. In zebra-state/src/service/finalized_state/zebra_…

▾ Sunlitzebra-state · zebra-stateEPSS 0.51%via NVD
CVE-2026-52739Medium· 5.9
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious block producer can terminate zebrad by placing the same shielded transaction in a non-finalized parent block and its child. In zebra-state/src/service/non_finali…

▾ Sunlitzebra-state · zebra-stateEPSS 0.52%via NVD
CVE-2026-52733Medium· 6.5
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave stale Sapling and Orchard note-commitment subtree roots in Zebra state. In zebra-state/src/service/non_finalized_state/…

▾ Sunlitzebra-state · zebra-stateEPSS 0.44%via NVD
CVEs tagged “ghsa” — page 43 · VulnSea