VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-53513Critical· 9.6
2mo ago

@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints

@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints

▾ Midnightbetter-auth · @better-auth/ssoEPSS 0.25%via GHSA
CVE-2026-53518High· 8.1
2mo ago

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

▾ Twilightbetter-auth · @better-auth/oauth-providerEPSS 0.41%via GHSA
GHSA-2vg6-77g8-24mpLow· 3.8
2mo ago

Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows

Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows

▾ Sunlitbetter-auth · better-authvia GHSA
GHSA-j8v8-g9cx-5qf4High· 8.3
2mo ago

@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers

@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers

▾ Twilightbetter-auth · @better-auth/scimvia GHSA
GHSA-59qp-cfj3-rp64Medium
2mo ago

netfoil has a domain name filter bypass via multiple questions

netfoil has a domain name filter bypass via multiple questions

▾ Sunlittinfoil-factory · github.com/tinfoil-factory/netfoilvia GHSA
GHSA-3g4q-2f67-2gvhLow
2mo ago

netfoil has a resource leak in LRU cache

netfoil has a resource leak in LRU cache

▾ Sunlittinfoil-factory · github.com/tinfoil-factory/netfoilvia GHSA
GHSA-7856-g3gv-9wq8Low
2mo ago

netfoil: Attacker controlled data written to logs

netfoil: Attacker controlled data written to logs

▾ Sunlittinfoil-factory · github.com/tinfoil-factory/netfoilvia GHSA
CVE-2026-53512Critical· 9.1
2mo ago

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

▾ Midnightbetter-auth · better-authEPSS 0.27%via GHSA
GHSA-fqf6-gxhh-2xhwHigh
2mo ago

uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)

uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)

▾ Twilightuucore · uucorevia GHSA
CVE-2025-46571Medium
2mo ago

Open WebUI allows limited stored XSS vila uploaded html file

Open WebUI allows limited stored XSS vila uploaded html file

▾ Sunlitopen-webui · open-webuiEPSS 0.35%via GHSA
CVE-2025-46719High
2mo ago

Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions

Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions

▾ Twilightopen-webui · open-webuiEPSS 0.54%via GHSA
CVE-2026-26192High· 7.3
2mo ago

Open WebUI vulnerable to Stored XSS via iFrame in citations model

Open WebUI vulnerable to Stored XSS via iFrame in citations model

▾ Twilightopen-webui · open-webuiEPSS 0.30%via GHSA
CVE-2026-26193High· 7.3
2mo ago

Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages

Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages

▾ Twilightopen-webui · open-webuiEPSS 0.30%via GHSA
CVE-2026-34225Medium· 4.3
2mo ago

Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality

Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality

▾ Sunlitopen-webui · open-webuiEPSS 0.30%via GHSA
CVE-2026-27823Critical
2mo ago

EGroupware has a Remote Code Execution Vulnerability

EGroupware has a Remote Code Execution Vulnerability

▾ Midnightegroupware · egroupware/egroupwareEPSS 0.97%via GHSA
CVE-2026-33655High· 7.7
2mo ago

New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs

New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs

▾ TwilightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.44%via GHSA
CVE-2026-40187High
2mo ago

EGroupware has Authenticated RCE via Malicious eTemplate Upload

EGroupware has Authenticated RCE via Malicious eTemplate Upload

▾ Twilightegroupware · egroupware/egroupwareEPSS 0.86%via GHSA
CVE-2026-44342Medium· 5.3
2mo ago

New API is vulnerable to CSRF through user email binding

New API is vulnerable to CSRF through user email binding

▾ SunlitQuantumNous · github.com/QuantumNous/new-apiEPSS 0.19%via GHSA
CVE-2026-44512Medium· 5.5
2mo ago

ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)

ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)

▾ Sunlitonnx · onnxEPSS 0.19%via OSV
CVE-2026-45016Medium· 6.5
2mo ago

EGroupware Vulnerable to Local File Inclusion via file:// URI in Mail Compose

EGroupware Vulnerable to Local File Inclusion via file:// URI in Mail Compose

▾ Sunlitegroupware · egroupware/egroupwarevia GHSA
CVE-2026-54234High· 7.5
2mo ago

vllm: vLLM: Denial of Service via malformed speculative decoding workload (CVE-2026-54234)

A flaw was found in vLLM, a high-throughput and memory-efficient inference and serving engine for Large Language Models (LLMs). A remote attacker can exploit this vulnerability by sending a specially crafted multi-request speculative decod…

▾ TwilightRed Hat · Red Hat AI Inference Server 3.4EPSS 0.62%via CSAF
GHSA-cgfv-jrfp-2r7vHigh
2mo ago

OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export

OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export

▾ Twilightopenremote · io.openremote:openremote-managervia GHSA
GHSA-qrwj-vh9x-gw5vHigh· 8.3
2mo ago

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write

▾ Twilightcoder · github.com/coder/coder/v2via GHSA
CVE-2026-35341High· 7.1
2mo ago

mkfifo: permissions of an existing file are changed after FIFO creation fails

mkfifo: permissions of an existing file are changed after FIFO creation fails

▾ Twilightuu_mkfifo · uu_mkfifoEPSS 0.14%via GHSA
CVE-2026-35361Low· 3.4
2mo ago

mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)

mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)

▾ Sunlituu_mknod · uu_mknodEPSS 0.14%via GHSA
CVE-2026-35381Low· 3.3
2mo ago

cut: -s ignored in -z -d '' newline-delimiter mode

cut: -s ignored in -z -d '' newline-delimiter mode

▾ Sunlituu_cut · uu_cutEPSS 0.15%via GHSA
CVE-2026-55501High· 7.3
2mo ago

9router: Login brute-force protection bypass via spoofed X-Forwarded-For header

9router: Login brute-force protection bypass via spoofed X-Forwarded-For header

▾ Twilight9router · 9routerEPSS 0.52%via GHSA
CVE-2026-54641High· 7.7
2mo ago

OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl

OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl

▾ Twilightopenremote · io.openremote:openremote-managervia GHSA
CVE-2026-54640High· 7.6
2mo ago

OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory

OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory

▾ Twilightopenremote · io.openremote:openremote-agentvia GHSA
CVE-2026-55076High· 7.4
2mo ago

Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking

Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.61%via GHSA
CVEs tagged “ghsa” — page 82 · VulnSea