VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-68518High
1mo ago

Glances is an open-source system cross-platform monitoring tool

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values before chevron.render(), allowing adjacent unescaped Mustache variables…

▾ Twilightglances · glancesEPSS 0.17%via NVD
CVE-2026-35219High
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, packages/server/src/automations/steps/zapier.ts, packages/server/src/automations/steps/n8n.ts, p…

▾ Twilightbudibase · @budibase/serverEPSS 0.46%via NVD
CVE-2026-61666High· 7.5
1mo ago

websocket-driver is a WebSocket protocol handler with pluggable I/O

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing …

▾ Twilightwebsocket-driver · websocket-driverEPSS 0.45%via NVD
CVE-2026-48053Medium· 5.8
1mo ago

Kolibri is an offline-first education platform

Kolibri is an offline-first education platform. Prior to version 0.19.4, several Kolibri API endpoints accept an unvalidated `baseurl` parameter and fetch attacker-controlled URLs from the Kolibri server, reflecting the response body bac…

▾ Sunlitkolibri · kolibriEPSS 0.38%via NVD
GHSA-wvxr-6v52-gfmhHigh· 8.8
1mo ago

Duplicate Advisory: Remote code execution via .zip file upload in Grav CMS

Duplicate Advisory: Remote code execution via .zip file upload in Grav CMS

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-cgvr-f65r-pjv3Medium· 5.4
1mo ago

Duplicate Advisory: Grav: Stored XSS via quoted-attribute bypass in detectXss

Duplicate Advisory: Grav: Stored XSS via quoted-attribute bypass in detectXss

▾ Sunlitgetgrav · getgrav/gravvia GHSA
CVE-2026-72832Medium· 5.4
1mo ago

Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php)

Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). The event-handler scan is anchored at `<` and uses `[^>]*?`, which c…

▾ Sunlitgetgrav · getgrav/gravEPSS 0.31%via NVD
CVE-2026-72819High· 8.8
1mo ago

Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code

Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can byp…

▾ Twilightgetgrav · getgrav/gravEPSS 0.90%via NVD
CVE-2026-73844Low· 3.7
1mo ago

CKAN MCP Server is a tool for querying CKAN open data portals

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception messages back to the caller instead of a sanitized, generic message. When the server…

▾ Sunlitaborruso · @aborruso/ckan-mcp-serverEPSS 0.36%via NVD
CVE-2026-73846Medium· 6.5
1mo ago

CKAN MCP Server is a tool for querying CKAN open data portals

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request parameters with unescaped ampersand, equals-sign, and vertical-bar delimiters, allowing differen…

▾ Sunlitaborruso · @aborruso/ckan-mcp-serverEPSS 0.19%via NVD
CVE-2026-73845Medium· 5.3
1mo ago

CKAN MCP Server is a tool for querying CKAN open data portals

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaServer to validate the server_url parameter with a pre…

▾ Sunlitaborruso · @aborruso/ckan-mcp-serverEPSS 0.38%via NVD
CVE-2026-10740Medium· 5.3
1mo ago

s2n-quic has excessive memory allocation

s2n-quic has excessive memory allocation

▾ Sunlits2n-quic · s2n-quicEPSS 0.29%via GHSA
CVE-2026-53657High· 8.2
1mo ago

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket

▾ Twilightlima-vm · github.com/lima-vm/lima/v2EPSS 0.20%via GHSA
CVE-2026-55153High· 7.1
1mo ago

mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"

mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"

▾ Twilightmchange · com.mchange:mchange-commons-javaEPSS 0.59%via GHSA
GHSA-8rw6-p7m8-63jpMedium· 6.5
1mo ago

SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users

SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users

▾ Sunlitsurrealdb · surrealdbvia GHSA
CVE-2026-35511High
1mo ago

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts

▾ Twilightauthorizerdev · github.com/authorizerdev/authorizervia GHSA
CVE-2026-50027Critical· 9.8
1mo ago

mcp-memory-service is a semantic memory layer for AI applications

mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with a…

▾ Midnightmcp-memory-service · mcp-memory-serviceEPSS 0.96%via NVD
CVE-2026-49457Critical· 9.1
1mo ago

erlang_quic is a pure Erlang QUIC implementation

erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not valida…

▾ Midnightquic · quicEPSS 0.25%via NVD
CVE-2026-49989Low
1mo ago

CrateDB is a distributed SQL database

CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they know, and can plant new blobs unconditionally, in any blob table, regardless of `GRANT`s…

▾ Sunlitcrate · io.crate:crateEPSS 0.47%via NVD
CVE-2026-49986High
1mo ago

The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code to the currently open project director…

The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code to the currently open project director…

▾ Twilightneuro-cortex-memory · neuro-cortex-memoryEPSS 0.16%via NVD
CVE-2026-49826Low
1mo ago

Concourse is a container-based automation system written in Go

Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in…

▾ Sunlitconcourse · github.com/concourse/concourseEPSS 0.53%via NVD
CVE-2026-50029Medium· 5.3
1mo ago

js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a key already exists in a parser-built container with `if (object[key])` instead of `if (key in object)`

js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a key already exists in a parser-built container with `if (object[key])` instead of `if (key in object)`. When the prior value is a falsy pri…

▾ Sunlitjs-toml · js-tomlEPSS 0.40%via NVD
CVE-2026-19730Medium· 4.2PoC
1mo ago

The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC

The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL defau…

▾ TwilightRed Hat · podmanEPSS 0.16%via NVD
CVE-2026-73558Medium· 5.3
1mo ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x * 2 * d in activation_kernels.cu can cause act_and_mul_kernel to consume another batched user's input, allowing a reque…

▾ Sunlitvllm · vllmvia NVD
CVE-2026-45819High· 7.5
1mo ago

baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.

baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.

▾ TwilightRed Hat · Red Hat Ceph Storage 9EPSS 0.51%via NVD
CVE-2026-73555Medium· 5.3
1mo ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts FastAPI RequestValidationError objects with str(exc), and sanitize_m…

▾ Sunlitvllm · vllmEPSS 0.42%via NVD
CVE-2026-73556Medium· 5.3⚖ disputed
1mo ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_format_enforcer.py is passed to lmformatenforcer.RegexParser without compi…

▾ Sunlitvllm · vllmvia NVD
CVE-2026-73557Medium
1mo ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. From 0.20.2rc0 until 0.26.0, safe_load_prompt_embeds in vllm/renderers/embed_utils.py uses torch.sparse.check_sparse_tensor_invariants, whose process-global save, enable,…

▾ Sunlitvllm · vllmEPSS 0.40%via NVD
CVE-2026-73842Critical· 9.0
1mo ago

OpenChoreo is a complete, open-source developer platform for Kubernetes

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requir…

▾ Midnightopenchoreo · github.com/openchoreo/openchoreoEPSS 0.27%via NVD
CVE-2026-73843Critical· 9.6
1mo ago

OpenChoreo is a complete, open-source developer platform for Kubernetes

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication,…

▾ Midnightopenchoreo · github.com/openchoreo/openchoreoEPSS 0.48%via NVD
CVEs tagged “ghsa” — page 46 · VulnSea