VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-50015High· 7.3
3mo ago

pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)

pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)

▾ Twilightpnpm · pnpmEPSS 0.43%via GHSA
CVE-2026-53520Medium· 6.5
3mo ago

Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing

Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing

▾ Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.40%via GHSA
CVE-2026-53521Medium· 6.4
3mo ago

Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context

Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context

▾ Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.31%via GHSA
CVE-2026-53519Critical· 9.1PoC
3mo ago

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key

▾ Abyssalnezhahq · github.com/nezhahq/nezhaEPSS 2.3%via GHSA
CVE-2026-54242Medium· 4.9
3mo ago

Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)

Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)

▾ Sunlitstatamic · statamic/cmsEPSS 0.23%via GHSA
CVE-2026-54243Medium· 6.1
3mo ago

Statamic Vulnerable to CSV formula injection in form submission exports

Statamic Vulnerable to CSV formula injection in form submission exports

▾ Sunlitstatamic · statamic/cmsEPSS 0.34%via GHSA
CVE-2026-53522Medium· 6.5
3mo ago

Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS

Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS

▾ Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.41%via GHSA
CVE-2026-53523Medium· 6.8
3mo ago

Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection

Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection

▾ Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.32%via GHSA
CVE-2026-54244Low· 3.5
3mo ago

Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors

Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors

▾ Sunlitstatamic · statamic/cmsEPSS 0.30%via GHSA
CVE-2026-53464Medium· 4.0
3mo ago

ImageMagick: Memory Leak in wand option parser when providing invalid arguments

ImageMagick: Memory Leak in wand option parser when providing invalid arguments

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.15%via GHSA
CVE-2026-53465Medium· 6.2
3mo ago

ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame image

ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame image

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.16%via GHSA
CVE-2026-55180Medium· 6.5
3mo ago

pnpm: Repository config can expand victim environment secrets into registry requests before scripts run

pnpm: Repository config can expand victim environment secrets into registry requests before scripts run

▾ Sunlitpnpm · pnpmEPSS 0.37%via GHSA
CVE-2026-55487High· 7.5
3mo ago

pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle

pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle

▾ Twilightpnpm · pnpmEPSS 0.18%via GHSA
CVE-2026-55697High· 7.5
3mo ago

pnpm: Repository-controlled configDependencies can select a pacquet native install engine

pnpm: Repository-controlled configDependencies can select a pacquet native install engine

▾ Twilightpnpm · pnpmEPSS 0.19%via GHSA
CVE-2026-49340High· 8.1
3mo ago

gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host

gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host

▾ Twilightgonic · go.senan.xyz/gonicEPSS 0.43%via GHSA
CVE-2026-49339High· 7.1
3mo ago

gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists

gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists

▾ Twilightgonic · go.senan.xyz/gonicEPSS 0.39%via GHSA
CVE-2026-49338High· 7.1
3mo ago

Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)

Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)

▾ Twilightgonic · go.senan.xyz/gonicEPSS 0.29%via GHSA
CVE-2026-55698High· 8.8
3mo ago

pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes

pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes

▾ Twilightpnpm · pnpmEPSS 0.30%via GHSA
CVE-2026-55699Medium· 6.5
3mo ago

pnpm: Reserved bin name deletes PNPM_HOME during global remove

pnpm: Reserved bin name deletes PNPM_HOME during global remove

▾ Sunlitpnpm · pnpmEPSS 0.45%via GHSA
CVE-2026-55700High· 7.1
3mo ago

pnpm: `stage download` writes outside its destination directory via manifest name/version traversal

pnpm: `stage download` writes outside its destination directory via manifest name/version traversal

▾ Twilightpnpm · pnpmEPSS 0.42%via GHSA
GHSA-ww5p-j6cj-6mqqMedium
3mo ago

Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API

Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API

▾ Sunlitnezhahq · github.com/nezhahq/nezhavia GHSA
CVE-2026-53462Medium· 5.9
3mo ago

ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails

ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.37%via GHSA
CVE-2026-44024Critical· 9.8PoC
3mo ago

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

▾ Abyssalfluentd · fluentdEPSS 1.1%via GHSA
CVE-2026-44025High· 7.5
3mo ago

Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API

Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API

▾ Twilightfluentd · fluentdEPSS 0.47%via GHSA
CVE-2026-44160High· 7.5
3mo ago

Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`

Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`

▾ Twilightfluentd · fluentdEPSS 0.62%via GHSA
CVE-2026-44161High· 7.2
3mo ago

Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`

Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`

▾ Twilightfluentd · fluentdEPSS 0.44%via GHSA
CVE-2026-46406Medium
3mo ago

@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write

@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write

▾ Sunlitanthropic-ai · @anthropic-ai/claude-codeEPSS 0.15%via GHSA
CVE-2026-46560High· 7.5
3mo ago

OpenAM: Unauthenticated Authentication Bypass via RADIUS Spoofing

OpenAM: Unauthenticated Authentication Bypass via RADIUS Spoofing

▾ Twilightopenidentityplatform · org.openidentityplatform.openam:openam-radiusvia GHSA
CVE-2026-48714Critical· 9.1
3mo ago

i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names

i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names

▾ Midnighti18next-http-middleware · i18next-http-middlewareEPSS 0.66%via GHSA
CVE-2026-48713Critical· 9.1
3mo ago

i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string

i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string

▾ Midnighti18next-fs-backend · i18next-fs-backendEPSS 0.66%via GHSA
CVEs tagged “ghsa” — page 94 · VulnSea