GitHub Security Advisories
Open-source package ecosystem coverage across npm / PyPI / Maven / Go / RubyGems and more.
33,882 advisories tracked · showing 100
- Aug 21, 2026GHSA-8hgv-xc77-jmcrMediumDisclosed before NVD
Grav: Page editors can inject arbitrary script into rendered pages via the Twig sandbox's assets.addJs/addCss allowlist, escalating to super-admin
- Aug 21, 2026GHSA-w4mq-xh27-6xpxMediumCVSS 4.1CVE-2026-63466
Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username
- Aug 21, 2026GHSA-5vf6-jrqr-78fjMediumCVSS 5.5CVE-2026-63004
Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers
- Aug 21, 2026GHSA-r5pq-6chh-j3xpHighCVSS 7.5CVE-2026-63462
Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
- Aug 21, 2026GHSA-64vf-r2xh-37w2MediumCVE-2026-27875
Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex...
- Aug 21, 2026GHSA-2p5p-hghg-98jwHighCVSS 7.8CVE-2026-41450
UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection...
- Aug 21, 2026GHSA-3v7p-hjjf-gqp8HighCVSS 7.8CVE-2026-41451
UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection...
- Aug 21, 2026GHSA-3j73-cvxw-c7p9unknownCVE-2026-69701
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-x922-wrhh-6rgcunknownCVE-2026-63726
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-mr6w-hqp3-cg59unknownCVE-2026-74580
In the Linux kernel, the following vulnerability has been resolved: vhost: reset the vring...
- Aug 21, 2026GHSA-m74v-pq49-phhfunknownCVE-2026-9244
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-6gvp-734j-c9vfunknownCVE-2026-9012
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-3qx8-6j6c-wwv4unknownCVE-2026-69099
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-74gp-gf6h-gmw2unknownCVE-2026-9321
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-7ph7-58w3-w755unknownCVE-2026-74581
In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed...
- Aug 21, 2026GHSA-6g47-hqw2-hv2runknownCVE-2026-74582
In the Linux kernel, the following vulnerability has been resolved: packet: use consistent...
- Aug 21, 2026GHSA-82fj-885j-3xg6HighCVE-2026-17250
A stack-based buffer overflow vulnerability exists in the firmware update functionality of TL...
- Aug 21, 2026GHSA-q49g-v5qg-r2xfunknownCVE-2026-9324
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-whg2-2j4x-jfcpHighCVE-2026-17252
A stack-based out-of-bounds write vulnerability exists in the login request handling...
- Aug 21, 2026GHSA-cfmx-mjrq-52xjHighCVE-2026-17251
A NULL pointer dereference vulnerability exists in the HTTP request parsing functionality of TL...
- Aug 21, 2026GHSA-qm4p-6qr9-f3w6unknownCVE-2026-74583
In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_route: fix...
- Aug 21, 2026GHSA-wcqh-23xq-vm77HighCVSS 7.8CVE-2026-41449
UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection...
- Aug 21, 2026GHSA-9572-6j7r-22rgunknownCVE-2026-11427
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-9r32-mr46-pfccunknownCVE-2023-7344
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-qh39-pj9p-f8w7HighCVSS 7.3CVE-2026-75933
Jet Admin allows an authenticated attacker to inject JavaScript via the sign-in page's scripts...
- Aug 21, 2026GHSA-cm72-j98h-q99gCriticalCVSS 8.6CVE-2026-75932
Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom...
- Aug 21, 2026GHSA-gxhw-82hv-hmccunknownCVE-2021-4482
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-mgwx-mmc7-794qunknownCVE-2023-7336
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-9fhc-g965-jvpqunknownCVE-2023-7310
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-m3p7-cfcr-85v7unknownCVE-2026-11902
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-fgh4-w64m-x32wunknownCVE-2021-4476
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-89fw-4vxh-h559unknownCVE-2021-4475
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-4x38-3vm4-2pv5unknownCVE-2026-11830
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-88qr-w79g-8qmmunknownCVE-2026-11938
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-mvmq-6425-4whjunknownCVE-2026-53991
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-m8h7-3c3q-3m8punknownCVE-2026-57835
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-fpvp-jgx3-4w9qCriticalCVSS 8.1CVE-2026-39909
llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's...
- Aug 21, 2026GHSA-7r8j-gpg6-pqwvunknownCVE-2026-53974
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-8f9f-5q3v-w62runknownCVE-2025-3127
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-rcq7-62cx-xmjrunknownCVE-2019-25725
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-cc49-67hv-4hv5CriticalCVSS 10.0CVE-2026-69502
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to...
- Aug 21, 2026GHSA-q5c7-jcmg-pvh6unknownCVE-2025-2795
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-w34g-hv5r-2hrpunknownCVE-2017-20232
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-9w2w-4hrg-qc23unknownCVE-2019-25715
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Aug 21, 2026GHSA-vh5m-r6vp-rxjgHighCVSS 8.5CVE-2026-22681
OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows...
- Aug 21, 2026GHSA-486p-g8x4-77mgMediumCVSS 7.1CVE-2026-49114
In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from...
- Aug 21, 2026GHSA-9339-3h6v-jp8cMediumCVSS 5.3CVE-2026-75928
The Brushfire platform's video content streaming application (https://online.brushfire.com)...
- Aug 21, 2026GHSA-gwmj-hf32-5v8vCriticalCVSS 9.6CVE-2026-77087
Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing...
- Aug 21, 2026GHSA-cw66-pfp5-82xpHighCVSS 7.5CVE-2026-77815
to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which...
- Aug 21, 2026GHSA-gh7r-589j-33x7CriticalCVE-2026-77812
DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth...
- Aug 21, 2026GHSA-f7wj-3v6p-grpvunknownCVE-2026-75501
A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router allows...
- Aug 21, 2026GHSA-6p87-gwpg-qp8wHighCVSS 7.5CVE-2026-77814
is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent...
- Aug 21, 2026GHSA-84gv-j7pq-p96wMediumCVE-2026-77028
Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect...
- Aug 21, 2026GHSA-6f22-4hxh-xrqhHighCVE-2026-76612
Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo <...
- Aug 21, 2026GHSA-42xr-8p7f-gqh6HighCVE-2026-75115
Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2...
- Aug 21, 2026GHSA-vmfm-wc5f-55m2CriticalCVE-2026-76613
Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5...
- Aug 21, 2026GHSA-q6g4-jq3h-365hHighCVE-2026-75946
A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior...
- Aug 21, 2026GHSA-9j4g-grw7-5966MediumCVE-2026-59654
Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped...
- Aug 21, 2026GHSA-5v96-p23j-5mwqMediumCVE-2026-77780
Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus...
- Aug 21, 2026GHSA-vgr8-rqwx-wqrpCriticalCVSS 9.8CVE-2026-77806
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as...
- Aug 21, 2026GHSA-j32c-fpr2-v6gmMediumCVE-2026-76611
Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery...
- Aug 21, 2026GHSA-6637-gh22-j6hqMediumCVE-2026-15580
vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows...
- Aug 21, 2026GHSA-2g95-5crg-wg8wMediumCVE-2026-77029
Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66
- Aug 21, 2026GHSA-h4jw-w55g-65gfMediumCVSS 4.2CVE-2026-59308
In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between...
- Aug 21, 2026GHSA-wmqr-wxf2-6449MediumCVSS 6.5CVE-2026-59318
In Spring AI's tool calling support, the per-request tool list is advertised to the model as a...
- Aug 21, 2026GHSA-4j5r-9p93-j2pxHighCVSS 8.6CVE-2026-77775
Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url...
- Aug 21, 2026GHSA-cw49-mhmj-m3xcHighCVE-2026-77759
Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow...
- Aug 21, 2026GHSA-5vg3-c628-vf56CriticalCVSS 9.1CVE-2026-77776
Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The...
- Aug 21, 2026GHSA-2g9x-r8w8-qjffHighCVSS 7.5CVE-2026-59279
The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit...
- Aug 21, 2026GHSA-pr5g-gw8g-vfpmLowCVSS 3.7CVE-2026-18356
The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against...
- Aug 21, 2026GHSA-w4ph-xfmv-g57qMediumCVSS 5.3CVE-2026-17559
The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths...
- Aug 21, 2026GHSA-g8mq-qr24-3qv3HighCVSS 6.5CVE-2026-77768
The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and...
- Aug 21, 2026GHSA-5r22-jfv5-3cpgHighCVSS 7.5CVE-2026-77767
Reconmap's API applies a fallback authorization policy in apps/api/app/Program.cs that requires...
- Aug 21, 2026GHSA-56h3-frqq-w75xMediumCVSS 5.3CVE-2026-15150
The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment...
- Aug 21, 2026GHSA-2f5q-8gh4-r39qMediumCVSS 4.2CVE-2026-15046
The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative...
- Aug 21, 2026GHSA-v7v5-h6rx-g9vqLowCVSS 2.7CVE-2026-13176
The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored...
- Aug 21, 2026GHSA-4v3w-374v-v8pxMediumCVSS 6.5CVE-2026-19848
The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile...
- Aug 21, 2026GHSA-mrm7-hxjw-vff5HighCVSS 6.5CVE-2026-77769
The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a...
- Aug 21, 2026GHSA-r6r4-9w99-4w36MediumCVSS 5.3CVE-2026-16650
The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square...
- Aug 21, 2026GHSA-2v74-j8j5-fw75HighCVE-2026-14208
Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory...
- Aug 21, 2026GHSA-8fww-64wc-46pfMediumCVE-2026-15576
Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated...
- Aug 21, 2026GHSA-2pgv-c2r7-f43rHighCVSS 6.5CVE-2026-77763
The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync...
- Aug 21, 2026GHSA-q62h-w723-22p2MediumCVE-2026-77761
A parser state isolation vulnerability in misp-stix could cause data from a previously processed...
- Aug 21, 2026GHSA-8jcv-3c3x-vwg4MediumCVSS 5.9CVE-2026-59296
Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or...
- Aug 21, 2026GHSA-hh37-xhg2-x62wHighCVSS 9.9CVE-2026-77683
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the...
- Aug 21, 2026GHSA-9rjx-wh4h-x9fjLowCVSS 5.4CVE-2026-77686
A weakness has been identified in Dolibarr up to 23.0.4. This affects an unknown part of the file...
- Aug 21, 2026GHSA-w7g2-952j-gmgrCriticalCVSS 9.1CVE-2026-77086
SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall...
- Aug 21, 2026GHSA-65gx-wjvj-88j8HighCVE-2026-77755
A denial-of-service vulnerability was identified in misp-stix when processing attacker-controlled...
- Aug 21, 2026GHSA-p279-35hc-hx5pHighCVSS 7.5CVE-2026-47827
Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to...
- Aug 21, 2026GHSA-wwv2-w4mm-82wmHighCVE-2026-77751
A path traversal vulnerability existed in the handling of MISP object template names during STIX...
- Aug 21, 2026GHSA-rj39-56xf-v987MediumCVSS 5.3CVE-2026-59323
An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is...
- Aug 21, 2026GHSA-r4gg-7w38-fj4jLowCVSS 6.3CVE-2026-77681
A vulnerability was identified in CodeAstro Online Job Portal 1.0. Affected by this vulnerability...
- Aug 21, 2026GHSA-6777-p72p-347gunknownCVE-2026-66797
Improper access control in CloudStack's annotation functionality allows unauthorized comment...
- Aug 21, 2026GHSA-pqpx-w6cx-7q9cMediumCVE-2026-77710
A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive...
- Aug 21, 2026GHSA-g5rw-pw9w-c288unknownCVE-2026-68745
Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0...
- Aug 21, 2026GHSA-v9cm-qf9w-m6c3unknownCVE-2026-66722
Improper authorization for CRUD operations on Project Roles and Project Role permissions for...
- Aug 21, 2026GHSA-2vq4-5w2v-frrgunknownCVE-2026-62440
Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin,...
- Aug 21, 2026GHSA-jc7r-r7p4-f656unknownCVE-2026-63046
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability...
- Aug 21, 2026GHSA-454g-wxrr-37fgunknownCVE-2026-66721
Missing authorization issue for domain admins in CloudStack's host tags listing functionality. ...
- Aug 21, 2026GHSA-xcmw-2mxf-7592unknownCVE-2026-65613
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's...