VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

GHSA-wvpp-8hx9-p66jHigh· 8.8
1mo ago

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-wg23-69c2-gjc8Critical
1mo ago

Craft CMS: Passkey login accepts replayed WebAuthn assertions

Craft CMS: Passkey login accepts replayed WebAuthn assertions

▾ Midnightcraftcms · craftcms/cmsvia GHSA
CVE-2026-62992Medium
1mo ago

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the 4.x line), Security::_checkDir() does not fully resolve symbolic links before validating…

▾ Sunlitsmarty · smarty/smartyEPSS 0.53%via NVD
CVE-2026-62996Medium
1mo ago

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-name handling does not adequately restrict which PHP stream wrappers an…

▾ Sunlitsmarty · smarty/smartyEPSS 0.51%via NVD
CVE-2026-69207Medium· 5.3
1mo ago

Hono is a Web application framework that provides support for any JavaScript runtime

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in CORS middleware, hono/cors, is vulnerable to a regular expression denial of service (ReDoS). During a preflight OPTIONS …

▾ Sunlithono · honoEPSS 0.61%via NVD
CVE-2026-48007High
1mo ago

Element Call is a native Matrix video conferencing application

Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, when configured to by a `posthog` key in config.json or by the `posthogApiHost` and `posthogApiKey`…

▾ Twilightelement-hq · @element-hq/element-call-embeddedEPSS 0.25%via NVD
CVE-2026-48039Critical· 9.1
1mo ago

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streama…

▾ Midnightmeta-ads-mcp · meta-ads-mcpEPSS 0.59%via NVD
CVE-2026-48170Critical· 9.1
1mo ago

`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`

`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`. After one such patch, `Object.protot…

▾ Midnightscim-patch · scim-patchEPSS 0.40%via NVD
GHSA-xxpx-f366-4xpqMedium
1mo ago

Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element

Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
GHSA-p8x7-9vfw-p7vcHigh
1mo ago

Craft CMS: Arbitrary user password reset leading to administrator account takeover

Craft CMS: Arbitrary user password reset leading to administrator account takeover

▾ Twilightcraftcms · craftcms/cmsvia GHSA
CVE-2026-71497Medium· 4.7
1mo ago

jsoup is a Java library for working with real-world HTML

jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing behavior of a dif…

▾ Sunlitjsoup · org.jsoup:jsoupEPSS 0.30%via NVD
CVE-2026-16633High
1mo ago

PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF

PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF

▾ Twilightpdfjs-dist · pdfjs-distvia GHSA
GHSA-w9hm-4m3m-fxmmHigh
1mo ago

ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633

ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633

▾ Twilightngx-extended-pdf-viewer · ngx-extended-pdf-viewervia GHSA
CVE-2026-71430Medium· 6.2
1mo ago

node-re2 provides RE2 regular expression bindings for Node.js

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty MaybeLocal that…

▾ SunlitRed Hat · re2EPSS 0.16%via NVD
CVE-2026-71498Medium· 5.1
1mo ago

node-re2 provides RE2 regular expression bindings for Node.js

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the native binding to read past the end of the…

▾ SunlitRed Hat · re2EPSS 0.17%via NVD
CVE-2026-67434High· 7.8
1mo ago

PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards

PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgbl…

▾ TwilightRed Hat · squizlabs/php_codesnifferEPSS 1.1%via NVD
GHSA-2rp4-x2j7-qmccMedium
1mo ago

Craft CMS: Stored XSS in the control panel via unescaped draft name

Craft CMS: Stored XSS in the control panel via unescaped draft name

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
GHSA-7hxc-f267-h5q7Low
1mo ago

Craft CMS: Incorrect path validation could potentially lead to path traversal

Craft CMS: Incorrect path validation could potentially lead to path traversal

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
GHSA-rvmm-v933-jgxqMedium
1mo ago

Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics

Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
GHSA-596p-6jv8-775vMedium
1mo ago

Craft CMS: Authenticated leak of secret environment variables

Craft CMS: Authenticated leak of secret environment variables

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
CVE-2026-71554Medium· 5.3PoC
1mo ago

h2 is a pure-Python implementation of a HTTP/2 protocol stack

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the co…

▾ Twilighth2 · h2EPSS 0.42%via NVD
GHSA-957r-qf9p-67xwMedium
1mo ago

Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts

Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
CVE-2026-71476High
1mo ago

Nx is a monorepo solution for TypeScript and polyglot codebases

Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache extracts downloaded cache artifacts without constraining where files are written. A malici…

▾ Twilightnx · nxEPSS 0.86%via NVD
CVE-2026-18654Medium· 6.8
1mo ago

AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands

AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands

▾ Sunlitawscli · awscliEPSS 0.29%via OSV
CVE-2026-54717Medium· 5.4
1mo ago

Silverstripe CMS is an open source content management system

Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when viewed using the page list view, because page titles are rendered into the breadcrumb t…

▾ Sunlitsilverstripe · silverstripe/cmsEPSS 0.34%via NVD
GHSA-5p4m-2wfm-xmqjHigh· 7.5
1mo ago

JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported

JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported

▾ Twilightjs-yaml · js-yamlvia GHSA
CVE-2026-71478Medium· 6.1
1mo ago

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage retur…

▾ Sunlitleague · league/commonmarkEPSS 0.36%via NVD
CVE-2026-71488High· 7.5
1mo ago

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing pa…

▾ Twilightleague · league/commonmarkEPSS 0.63%via NVD
GHSA-g2gp-3wwq-f4phHigh· 7.5
1mo ago

league/commonmark: Denial of service via adjacent inline attribute blocks

league/commonmark: Denial of service via adjacent inline attribute blocks

▾ Twilightleague · league/commonmarkvia GHSA
GHSA-jfm3-95jq-q3rfHigh· 7.5
1mo ago

league/commonmark: Denial of service via duplicate footnote definitions

league/commonmark: Denial of service via duplicate footnote definitions

▾ Twilightleague · league/commonmarkvia GHSA
CVEs tagged “ghsa” — page 50 · VulnSea