-
Notifications
You must be signed in to change notification settings - Fork 730
Pull requests: github/advisory-database
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[GHSA-mpx4-jmpr-vm8v] PGHoard: Password written to debug log
#9298
opened Sep 1, 2026 by
kgnio
Loading…
[GHSA-ch4j-vcf5-58x5] Cockpit CMS: Stored cross-site scripting vulnerability in the Set field type's Display template option
#9297
opened Sep 1, 2026 by
kgnio
Loading…
[GHSA-4w3x-69m8-478c] A flaw was found in the role-users endpoint of the...
#9296
opened Sep 1, 2026 by
ottotouzil
Loading…
[GHSA-v4g2-cm5v-cxv7] Digital products download without proper payment status check
#9295
opened Sep 1, 2026 by
nikpivkin
Loading…
[GHSA-wrvx-pxxf-g8fg] Insufficient Session Expiration vulnerability in Apache T...
#9293
opened Sep 1, 2026 by
oscerd
Loading…
[GHSA-h3mr-2w3q-jcv9] Time-of-check Time-of-use (TOCTOU) Race Condition vulnera...
#9292
opened Sep 1, 2026 by
oscerd
Loading…
[GHSA-82jr-6mfr-9vq5] Uncontrolled Resource Consumption vulnerability in Apache...
#9291
opened Sep 1, 2026 by
oscerd
Loading…
[GHSA-gcx9-497g-6cp6] Improper Access Control, Incorrect Authorization vulnerab...
#9290
opened Sep 1, 2026 by
oscerd
Loading…
[GHSA-w3xg-786f-g788] Improper Authorization vulnerability in Apache Tomcat cau...
#9289
opened Sep 1, 2026 by
oscerd
Loading…
[GHSA-h3x4-894j-xpx5] Incorrect Authorization vulnerability in Apache Tomcat's ...
#9288
opened Sep 1, 2026 by
oscerd
Loading…
[GHSA-g8qj-vp23-742m] Off-by-one Error vulnerability in Apache Tomcat impacting...
#9287
opened Sep 1, 2026 by
oscerd
Loading…
[GHSA-9xv2-5v5q-p794] Authentication Bypass by Capture-replay vulnerability in ...
#9286
opened Sep 1, 2026 by
oscerd
Loading…
[GHSA-5q6q-ffrq-6xfc] Improper Authentication vulnerability in Apache Tomcat me...
#9285
opened Sep 1, 2026 by
oscerd
Loading…
[GHSA-r635-g3xr-vw7x] Socket.IO: Engine.IO Polling Transport Connection Exhaustion
#9284
opened Sep 1, 2026 by
abdelkabirouadoukou
Loading…
[GHSA-f97c-ph8j-8vff] Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation
#9283
opened Sep 1, 2026 by
nikpivkin
Loading…
[GHSA-mvxj-8qhj-g2wr] Unauthenticated Server Side Request Forgery (SSRF) in...
#9281
opened Aug 31, 2026 by
princess38827
Loading…
[GHSA-q9r5-6hrr-9ph7] Hugging Face smolagents: Unsafe deserialization in Remote Python Executor leads to RCE
#9280
opened Aug 31, 2026 by
sfblackl-intel
Loading…
[GHSA-g8rv-gp9f-q875] IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2...
#9279
opened Aug 31, 2026 by
Michael-JRead
Loading…
[GHSA-2r2c-cx56-8933] JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
#9278
opened Aug 31, 2026 by
dolores193
Loading…
[GHSA-47qp-hqvx-6r3f] JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
#9277
opened Aug 31, 2026 by
dolores193
Loading…
[GHSA-m2h6-j472-rp4c] python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
#9274
opened Aug 31, 2026 by
frenzymadness
Loading…
[GHSA-6x9p-4r67-5gjx] Budibase authenticated arbitrary S3 signed upload URL issuance via
/api/attachments/:datasourceId/url
#9273
opened Aug 31, 2026 by
kgnio
Loading…
[GHSA-mq36-523m-x7vv] node-opcua missing nonce verification in UserNameIdentityToken authentication
#9272
opened Aug 31, 2026 by
kgnio
Loading…
Previous Next
ProTip!
Filter pull requests by the default branch with base:main.