VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-52804Medium
3mo ago

Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation

Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation

▾ Sunlitgogs · gogs.io/gogsEPSS 0.50%via GHSA
CVE-2026-52805High· 8.7
3mo ago

Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft

Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft

▾ Twilightgogs · gogs.io/gogsEPSS 0.38%via GHSA
CVE-2026-52806Critical· 9.9PoC
3mo ago

Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge

Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge

▾ Abyssalgogs · gogs.io/gogsEPSS 7.9%via GHSA
CVE-2026-52807High
3mo ago

Gogs has DOM-based XSS via Milestone Name on New Issue Page

Gogs has DOM-based XSS via Milestone Name on New Issue Page

▾ Twilightgogs · gogs.io/gogsEPSS 0.48%via GHSA
CVE-2026-52808High· 7.1
3mo ago

Gogs's write-level collaborators can mutate admin-only repository settings via API

Gogs's write-level collaborators can mutate admin-only repository settings via API

▾ Twilightgogs · gogs.io/gogsEPSS 0.48%via GHSA
CVE-2026-52809Medium· 6.8
3mo ago

Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES

Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES

▾ Sunlitgogs · gogs.io/gogsEPSS 0.20%via GHSA
CVE-2026-52810HighPoC
3mo ago

Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion

Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion

▾ Midnightgogs · gogs.io/gogsEPSS 0.43%via GHSA
CVE-2026-52811Critical
3mo ago

Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym

Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym

▾ Midnightgogs · gogs.io/gogsEPSS 0.47%via GHSA
CVE-2026-52812High
3mo ago

Gogs: LFS dedupe path leaks private repo content across tenants

Gogs: LFS dedupe path leaks private repo content across tenants

▾ Twilightgogs · gogs.io/gogsEPSS 0.24%via GHSA
CVE-2026-52813Critical· 10.0PoC
3mo ago

Gogs has Path Traversal in organization name that results in RCE through Git hooks

Gogs has Path Traversal in organization name that results in RCE through Git hooks

▾ Abyssalgogs · gogs.io/gogsEPSS 1.1%via GHSA
CVE-2026-52814Medium
3mo ago

Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)

Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)

▾ Sunlitgogs · gogs.io/gogsEPSS 0.55%via GHSA
CVE-2026-52815MediumPoC
3mo ago

Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API

Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API

▾ Twilightgogs · gogs.io/gogsEPSS 1.5%via GHSA
CVE-2026-45049High· 8.3
3mo ago

OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet

OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet

▾ Twilightopenidentityplatform · org.openidentityplatform.openam:openam-federationvia GHSA
CVE-2026-52816Medium
3mo ago

Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS

Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS

▾ Sunlitgogs · gogs.io/gogsEPSS 0.68%via GHSA
CVE-2026-55173High· 8.1
3mo ago

AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink

AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink

▾ Twilightwwbn · wwbn/avideoEPSS 3.4%via GHSA
CVE-2026-54350Critical· 10.0PoC
3mo ago

Budibase has nonymous NoSQL operator injection via published-app query templates

Budibase has nonymous NoSQL operator injection via published-app query templates

▾ Abyssalbudibase · @budibase/serverEPSS 0.54%via GHSA
CVE-2026-53925High· 7.8
3mo ago

Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration

Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration

▾ Twilightglances · glancesEPSS 0.18%via GHSA
CVE-2026-54134High
3mo ago

OctoPrint has possible file exfiltration via query parameters on upload endpoints

OctoPrint has possible file exfiltration via query parameters on upload endpoints

▾ TwilightOctoPrint · OctoPrintEPSS 0.32%via GHSA
CVE-2026-54557Medium· 5.5
3mo ago

mise HTTP backend uses raw version path for install symlink destination

mise HTTP backend uses raw version path for install symlink destination

▾ Sunlitmise · miseEPSS 0.17%via GHSA
CVE-2026-55441High· 8.6
3mo ago

Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository

Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository

▾ Twilightmise · miseEPSS 0.18%via GHSA
CVE-2026-55448Medium· 6.3
3mo ago

Mise's local credential_command executes untrusted config

Mise's local credential_command executes untrusted config

▾ Sunlitmise · miseEPSS 0.16%via GHSA
CVE-2026-55488High
3mo ago

motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read

motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read

▾ Twilightmotioneye · motioneyeEPSS 0.62%via GHSA
GHSA-qxvg-h7q2-hcxhCritical· 9.8
3mo ago

motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)

motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)

▾ Midnightmotioneye · motioneyevia GHSA
GHSA-phv5-334h-mxcwCritical
3mo ago

motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal

motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal

▾ Midnightmotioneye · motioneyevia GHSA
GHSA-7cqp-7cfv-6c3qMedium
3mo ago

AVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel

AVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel

▾ Sunlitwwbn · wwbn/avideovia GHSA
CVE-2026-54518Medium· 6.5
3mo ago

jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass (CVE-2026-54518)

A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass security view restrictions by sending specially crafted JSON (JavaScript Object Notation) data. The UnwrappedPropertyHandler component, which proce…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.35%via CSAF
CVE-2026-50193High· 7.5
3mo ago

jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing (CVE-2026-50193)

A flaw was found in jackson-databind, a general-purpose data-binding library for Jackson Data Processor. A remote attacker can exploit this vulnerability by sending deeply nested JSON (JavaScript Object Notation) data to a service that rea…

▾ TwilightRed Hat · Red Hat JBoss EAP 7.4 ELS for RHEL 8EPSS 0.62%via CSAF
CVE-2026-54512High· 8.1PoC
3mo ago

jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)

A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass the PolymorphicTypeValidator (PTV) when polymorphic typing is enabled and a type identifier contains generic parameters. By crafting a malicious ty…

▾ MidnightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 1.00%via CSAF
CVE-2026-54513High· 8.1
3mo ago

jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513)

A flaw was found in jackson-databind, a library used for processing data. This vulnerability allows an attacker to bypass security controls designed to validate data types. By sending specially crafted input, an attacker can force the syst…

▾ TwilightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 1.2%via CSAF
CVE-2026-54514Medium· 5.3
3mo ago

jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution (CVE-2026-54514)

A flaw was found in jackson-databind, a library used for processing JSON data. This vulnerability allows a remote attacker to force the application to perform an attacker-chosen DNS (Domain Name System) query. This occurs when untrusted JS…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.37%via CSAF
CVEs tagged “ghsa” — page 98 · VulnSea