-
Notifications
You must be signed in to change notification settings - Fork 729
Pull requests: github/advisory-database
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[GHSA-mvxj-8qhj-g2wr] Unauthenticated Server Side Request Forgery (SSRF) in...
#9281
opened Aug 31, 2026 by
princess38827
Loading…
[GHSA-q9r5-6hrr-9ph7] Hugging Face smolagents: Unsafe deserialization in Remote Python Executor leads to RCE
#9280
opened Aug 31, 2026 by
sfblackl-intel
Loading…
[GHSA-g8rv-gp9f-q875] IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2...
#9279
opened Aug 31, 2026 by
Michael-JRead
Loading…
[GHSA-2r2c-cx56-8933] JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
#9278
opened Aug 31, 2026 by
dolores193
Loading…
[GHSA-47qp-hqvx-6r3f] JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
#9277
opened Aug 31, 2026 by
dolores193
Loading…
[GHSA-m2h6-j472-rp4c] python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
#9274
opened Aug 31, 2026 by
frenzymadness
Loading…
[GHSA-6x9p-4r67-5gjx] Budibase authenticated arbitrary S3 signed upload URL issuance via
/api/attachments/:datasourceId/url
#9273
opened Aug 31, 2026 by
kgnio
Loading…
[GHSA-mq36-523m-x7vv] node-opcua missing nonce verification in UserNameIdentityToken authentication
#9272
opened Aug 31, 2026 by
kgnio
Loading…
[GHSA-73mf-m39p-wpm9] Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)
#9271
opened Aug 30, 2026 by
dechapon25
Loading…
[GHSA-wgx6-g857-jjf7] openc3: correct the 7.0.x RubyGems fixed version to 7.0.0.pre.rc3
#9266
opened Aug 28, 2026 by
pacocartones
Loading…
[GHSA-v529-vhwc-wfc5] openc3: correct RubyGems fixed version to 7.0.0.pre.rc3
#9265
opened Aug 28, 2026 by
pacocartones
Loading…
[GHSA-4jvx-93h3-f45h] openc3: correct the 7.0.x RubyGems fixed version to 7.0.0.pre.rc3
#9264
opened Aug 28, 2026 by
pacocartones
Loading…
[GHSA-2wvh-87g2-89hr] openc3: correct RubyGems fixed version to 7.0.0.pre.rc3
#9263
opened Aug 28, 2026 by
pacocartones
Loading…
GHSA-9cr8-q42q-g8m7: add missing 3.6 branch range, correct v2 fixed version, fix package name
#9262
opened Aug 28, 2026 by
rezmoss
Loading…
[GHSA-vw47-79jv-3598] Adobe Commerce Improper Authorization vulnerability
#9261
opened Aug 28, 2026 by
kgnio
Loading…
[GHSA-3cfg-w257-cgf8] Magento Information Exposure vulnerability
#9260
opened Aug 28, 2026 by
kgnio
Loading…
[GHSA-539v-w87w-w62c] Magento Improper Access Control vulnerability
#9259
opened Aug 28, 2026 by
kgnio
Loading…
[GHSA-656q-fx2w-8ccv] Magento Improper Access Control vulnerability
#9258
opened Aug 28, 2026 by
kgnio
Loading…
[GHSA-v7vf-f5q6-m899] .NET Remote Code Execution Vulnerability
#9257
opened Aug 28, 2026 by
kgnio
Loading…
[GHSA-6ff8-jrfg-43hh] Magento Business Logic Error vulnerability
#9254
opened Aug 28, 2026 by
kgnio
Loading…
[GHSA-w4f7-4cxr-rv3c] cowboy and gun affected by an HTTP Request/Response Splitting vulnerability
#9253
opened Aug 28, 2026 by
dbii
Loading…
[GHSA-f88m-g3jw-g9cj] Add CVE-2026-69242 inherited from libvips
#9252
opened Aug 27, 2026 by
SirHegel
Loading…
[GHSA-9pwm-6667-rfcm] General user can mint admin access tokens via /access-tok...
#9249
opened Aug 27, 2026 by
oscerd
Loading…
Previous Next
ProTip!
Add no:assignee to see everything that’s not assigned.