VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3810 CVEsRSS

CVE-2026-61833High· 8.1PoC
1w ago

zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification

zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior to 2.1.18, the bearer authentication handler in pkg/api/authn.go maps every HTTP method other than GET and HEAD to th…

▾ Midnightproject-zot · zotEPSS 0.51%via NVD
CVE-2026-81505High· 7.1PoC
1w ago

Convoy is a cloud native webhooks gateway

Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint authorizes access to the project in the URL, but Handler.GetSource calls sources.Service.FindSourceByID() a…

▾ Midnightfrain-dev · github.com/frain-dev/convoyEPSS 0.46%via NVD
CVE-2026-61794Medium· 6.8PoC
1w ago

Capsule is a multi-tenancy and policy-based framework for Kubernetes

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update validation in internal/webhook/tenant/validation/forbidden_annotations_regex.go compiles ForbiddenLabels.Regex for both the…

▾ Twilightprojectcapsule · capsuleEPSS 0.59%via NVD
CVE-2026-61795Medium· 6.8
1w ago

Capsule is a multi-tenancy and policy-based framework for Kubernetes

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, hostnameRegexHandler.OnUpdate in internal/webhook/tenant/validation/hostname_regex.go reverses the new and old Tenant parameters and validate…

▾ Sunlitprojectcapsule · capsuleEPSS 0.59%via NVD
CVE-2026-61672High· 7.1PoC
1w ago

Capsule is a multi-tenancy and policy-based framework for Kubernetes

Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in pkg/api/forbidden_list.go sorts denied metadata keys case-insensitively and then uses sort.SearchStrings, which assume…

▾ Midnightprojectcapsule · capsuleEPSS 0.33%via NVD
CVE-2026-77339Medium· 5.1PoC
1w ago

Process Compose is a scheduler and orchestrator for non-containerized applications

Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listener in src/mcp/server.go accepts browser-origin requests to /sse and the returned message endpoint without validating …

▾ Twilightf1bonacc1 · github.com/f1bonacc1/process-composeEPSS 0.26%via NVD
CVE-2026-58197High· 8.8PoC
1w ago

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission pro…

▾ Midnightstacklok · github.com/stacklok/toolhiveEPSS 0.37%via NVD
CVE-2026-77301High· 7.5PoC
1w ago

adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js

adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEntry.js trusts an entry's central-directory uncompressed size and allocates output memory before validating that value …

▾ Midnightadm-zip · adm-zipEPSS 0.61%via NVD
CVE-2026-77606Medium· 6.1
1w ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when `headers=plain`, table header text was emitted into `<th>` via a raw HTML path. U…

▾ Sunlitmediawiki · mediawiki/semantic-media-wikiEPSS 0.26%via NVD
CVE-2026-77608Medium· 6.1
1w ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when the `value` parameter was reflected back into rendered output and error messaging…

▾ SunlitSemanticMediaWiki · SemanticMediaWikiEPSS 0.26%via NVD
CVE-2026-61682Critical· 9.9
1w ago

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* i…

▾ Midnightkcp-dev · kcpEPSS 0.38%via NVD
CVE-2025-61682High· 8.6PoC
1w ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as…

▾ Midnightmediawiki · mediawiki/semantic-media-wikiEPSS 0.29%via NVD
CVE-2025-53837Critical· 9.9
1w ago

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc)

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile o…

▾ Midnightxwiki · xwiki-renderingEPSS 0.64%via NVD
CVE-2026-62282Medium· 6.5PoC
1w ago

OpenCVE is a vulnerability intelligence platform

OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack integrations does not sufficiently validate user-supplied HTTP or HTTPS destinations. An authenticated user with permiss…

▾ Twilightopencve · opencveEPSS 0.42%via NVD
CVE-2026-54147Medium· 6.5
1w ago

http4k is a functional toolkit for Kotlin HTTP applications

http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest ignores its configured algorithm parameter and verifies every Digest response wit…

▾ Sunlithttp4k · http4kEPSS 0.26%via NVD
CVE-2026-54148High· 8.1
1w ago

http4k is a functional toolkit for Kotlin HTTP applications

http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in an Authorization: Digest response with the …

▾ Twilighthttp4k · http4kEPSS 0.58%via NVD
CVE-2026-72697High· 6.5
1w ago

Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content

Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content

▾ Twilightgetgrav · getgrav/gravEPSS 0.46%via GHSA
GHSA-xjw9-38cr-6372High
1w ago

djust: A template binding inherits a context safety grant it never earned (XSS)

djust: A template binding inherits a context safety grant it never earned (XSS)

▾ Twilightdjust · djustvia OSV
GHSA-9395-2g46-rj3fHigh
1w ago

djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)

djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)

▾ Twilightdjust · djustvia OSV
CVE-2026-72695High· 8.1
1w ago

Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion

Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion

▾ Twilightgetgrav · getgrav/gravEPSS 0.90%via GHSA
CVE-2026-86049High· 7.1
1w ago

Jupyter Server is the backend for Jupyter web applications

Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into a JSON header block without applying the token scrubbing used for t…

▾ Twilightjupyter-server · jupyter_serverEPSS 0.42%via NVD
CVE-2026-77615High· 8.7PoC
1w ago

Paella Player is a set of libraries to create a multi stream video player

Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability i…

▾ Midnightopencast · opencastEPSS 0.56%via NVD
CVE-2026-77281Medium· 6.5
1w ago

Caddy is an extensible server platform that uses TLS by default

Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. In modules/caddyhttp/rewrite/rewrite.go, Rewrite.Rewrite()…

▾ Sunlitcaddyserver · caddyEPSS 0.49%via NVD
CVE-2026-45140Critical· 9.8PoC
1w ago

Chamilo LMS is an open-source learning management system

Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, …

▾ Abyssalchamilo · chamilo-lmsEPSS 1.3%via NVD
CVE-2026-72702Low
1w ago

Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match

Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match

▾ Sunlitgetgrav · getgrav/gravEPSS 0.15%via GHSA
CVE-2026-72701Low· 3.7
1w ago

Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protection

Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protection

▾ Sunlitgetgrav · getgrav/gravEPSS 0.28%via GHSA
CVE-2026-72698High· 6.5
1w ago

Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths

Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths

▾ Twilightgetgrav · getgrav/gravEPSS 0.41%via GHSA
CVE-2026-76846High· 7.5
1w ago

Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled

Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled

▾ Twilightgetgrav · getgrav/gravEPSS 0.41%via GHSA
CVE-2026-76839High· 7.7
1w ago

Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()

Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()

▾ Twilightgetgrav · getgrav/gravEPSS 0.47%via GHSA
CVE-2026-68537High· 7.5
1w ago

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into…

▾ Twilightfulgur-rs · fulgurEPSS 0.61%via NVD
CVEs tagged “ghsa” — page 8 · VulnSea