VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-57299Medium· 4.3
3mo ago

Missing permission checks in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allow attackers with Overall/Read permission to enumerate the names of configured Contrast metadata.

Missing permission checks in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allow attackers with Overall/Read permission to enumerate the names of configured Contrast metadata.

▾ Sunlitjenkins · contrast_continuous_application_securityEPSS 0.25%via NVD
CVE-2026-57297Medium· 4.3
3mo ago

A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, a…

A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, a…

▾ Sunlitjenkins · contrast_continuous_application_securityEPSS 0.25%via NVD
CVE-2026-12537High· 7.8⚖ disputed
3mo ago

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker …

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker …

▾ Twilightgoogle · gemini-cliEPSS 0.21%via NVD
CVE-2026-48708High· 7.5
3mo ago

OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination

OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination

▾ TwilightOliveTin · github.com/OliveTin/OliveTinEPSS 0.54%via GHSA
CVE-2026-48709Low· 3.7
3mo ago

OliveTin: ValidateArgumentType API Endpoint's Missing Authentication Allows Action and Argument Enumeration

OliveTin: ValidateArgumentType API Endpoint's Missing Authentication Allows Action and Argument Enumeration

▾ SunlitOliveTin · github.com/OliveTin/OliveTinEPSS 0.42%via GHSA
GHSA-98gv-6gmj-cm6mLow
3mo ago

Duplicate Advisory: ImageMagick: Memory leak in coders/txt.c without freetype

Duplicate Advisory: ImageMagick: Memory leak in coders/txt.c without freetype

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-8g9f-ccmr-vfvgMedium· 3.7
3mo ago

Duplicate Advisory: ImageMagick has a possible heap Use After Free vulnerability in its meta coder

Duplicate Advisory: ImageMagick has a possible heap Use After Free vulnerability in its meta coder

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-v772-658q-978pLow
3mo ago

Duplicate Advisory: ImageMagick: SVG-to-MVG Command Injection via coders/svg.c

Duplicate Advisory: ImageMagick: SVG-to-MVG Command Injection via coders/svg.c

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
CVE-2026-50221Medium· 5.4
3mo ago

OpenStack Swift vulnerable to authenticated server-side request forgery

OpenStack Swift vulnerable to authenticated server-side request forgery

▾ Sunlitswift · swiftEPSS 0.22%via OSV
CVE-2026-10609Medium· 6.8
3mo ago

OpenShift Cluster Logging Operator missing authorization flaw

OpenShift Cluster Logging Operator missing authorization flaw

▾ Sunlitopenshift · github.com/openshift/cluster-logging-operatorEPSS 0.38%via OSV
GHSA-vjr9-f93j-mjr7High· 8.1
3mo ago

Duplicate Advisory: OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

Duplicate Advisory: OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

▾ Twilightopenremote · io.openremote:openremote-managervia GHSA
GHSA-55cm-p4ww-685gMedium· 5.3
3mo ago

Duplicate Advisory: Hono missing validation of cookie name on write path in setCookie()

Duplicate Advisory: Hono missing validation of cookie name on write path in setCookie()

▾ Sunlithono · honovia GHSA
GHSA-w4hm-rrxg-pxcfMedium· 7.1
3mo ago

Duplicate Advisory: Flowise Execute Flow function has an SSRF vulnerability

Duplicate Advisory: Flowise Execute Flow function has an SSRF vulnerability

▾ Sunlitflowise · flowisevia GHSA
GHSA-2x6f-57hp-86fxMedium· 5.5
3mo ago

Duplicate Advisory: Nuxt dev server vite-node IPC socket is world-connectable on Linux

Duplicate Advisory: Nuxt dev server vite-node IPC socket is world-connectable on Linux

▾ Sunlitnuxt · nuxtvia GHSA
GHSA-g7vj-qw6x-g3p8Critical· 9.8
3mo ago

Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist

Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist

▾ Midnightpicklescan · picklescanvia GHSA
GHSA-32fw-h446-j4hhHigh· 6.5
3mo ago

Duplicate Advisory: Grav is Vulnerable to XXE via SVG Upload

Duplicate Advisory: Grav is Vulnerable to XXE via SVG Upload

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-q8qp-8jq6-78mcHigh· 8.1
3mo ago

Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

▾ Twilightpicklescan · picklescanvia GHSA
GHSA-gq8p-2329-gh3xHigh· 8.1
3mo ago

Duplicate Advisory: Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

Duplicate Advisory: Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

▾ Twilightpicklescan · picklescanvia GHSA
GHSA-x36p-c636-788xHigh· 8.1
3mo ago

Duplicate Advisory: Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

Duplicate Advisory: Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

▾ Twilightpicklescan · picklescanvia GHSA
GHSA-mg57-j93w-g3c7High· 8.1
3mo ago

Duplicate Advisory: Picklescan has a missing detection when calling built-in python profile.Profile.runctx

Duplicate Advisory: Picklescan has a missing detection when calling built-in python profile.Profile.runctx

▾ Twilightpicklescan · picklescanvia GHSA
GHSA-pvrg-q6jw-42p7High· 7.5
3mo ago

Duplicate Advisory: Traefik vulnerable to HTTP/2 request causing denial of service

Duplicate Advisory: Traefik vulnerable to HTTP/2 request causing denial of service

▾ Twilighttraefik · github.com/traefik/traefikvia GHSA
CVE-2026-41862High· 8.8
3mo ago

Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to re…

Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to re…

▾ Twilightbroadcom · spring_statemachineEPSS 0.76%via NVD
CVE-2026-12866Critical· 9.8
3mo ago

expr-eval vulnerable to Code Execution

expr-eval vulnerable to Code Execution

▾ Midnightexpr-eval · expr-evalEPSS 0.87%via GHSA
CVE-2023-54365High· 7.5
3mo ago

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' techniqu…

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' techniqu…

▾ Twilighttraefik · traefikEPSS 0.77%via NVD
CVE-2026-9073Medium· 6.2
3mo ago

A flaw was found in foreman-mcp-server

A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs session identifiers, which are treated as authentication creden…

▾ Sunlitredhat · satelliteEPSS 0.21%via NVD
CVE-2026-56379High· 8.1
3mo ago

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector G…

▾ Twilightimagemagick · imagemagickEPSS 1.6%via NVD
CVE-2026-56371Medium· 5.3
3mo ago

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each…

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each…

▾ Sunlitimagemagick · imagemagickEPSS 0.44%via NVD
CVE-2026-52800High· 8.8
3mo ago

Gogs Vulnerable to CSRF Leading to Organization Owner Takeover

Gogs Vulnerable to CSRF Leading to Organization Owner Takeover

▾ Twilightgogs · gogs.io/gogsEPSS 0.25%via GHSA
CVE-2026-52801High· 8.1
3mo ago

Gogs has the ability to import local repositories via Mirror Settings

Gogs has the ability to import local repositories via Mirror Settings

▾ Twilightgogs · gogs.io/gogsEPSS 0.57%via GHSA
CVE-2026-52802Medium· 5.4
3mo ago

Gogs has an Open Redirect via redirect_to

Gogs has an Open Redirect via redirect_to

▾ Sunlitgogs · gogs.io/gogsEPSS 0.55%via GHSA
CVEs tagged “ghsa” — page 97 · VulnSea