Vulnerabilities

Recent vulnerabilities

Recent vulnerabilities from
Select from 81 available sources using the dropdown above.

GitHub 🐙

Recent vulnerabilities · 380173 entries
ID Severity Description Published Updated
ghsa-r8x8-66rr-q5w2
5.4 (3.1)
5.3 (4.0)
OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers abl… 2026-10-03T15:30:26Z 2026-10-03T15:30:26Z
ghsa-j3m5-w9gh-35hx
7.1 (3.1)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability … 2026-10-03T15:30:26Z 2026-10-03T15:30:26Z
ghsa-86x4-hjp8-8h99
4.9 (3.1)
6.9 (4.0)
OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated adminis… 2026-10-03T15:30:26Z 2026-10-03T15:30:26Z
ghsa-3ggw-53qv-qjmj
8.2 (3.1)
Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Acce… 2026-10-03T15:30:26Z 2026-10-03T15:30:26Z
ghsa-mxvw-rw3m-5c33
4.7 (3.1)
2.3 (4.0)
OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers … 2026-10-03T15:30:25Z 2026-10-03T15:30:25Z
ghsa-mf8f-w84m-x4gc
6.8 (3.1)
7.6 (4.0)
OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests wh… 2026-10-03T15:30:25Z 2026-10-03T15:30:25Z
ghsa-55ch-4xvx-7w9q
4.9 (3.1)
6.9 (4.0)
OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint q… 2026-10-03T15:30:25Z 2026-10-03T15:30:25Z
ghsa-35wg-cp3w-fh5v
6.1 (3.1)
5.3 (4.0)
OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated … 2026-10-03T15:30:25Z 2026-10-03T15:30:25Z
ghsa-xjpm-v974-vhq4
5.3 (3.1)
6.0 (4.0)
Nezha from 1.8.0 before 2.3.13 contains a lock-order inversion in UpdateGroup and DeleteGroup that … 2026-10-03T15:30:24Z 2026-10-03T15:30:24Z
ghsa-wxcf-pvf2-p2h6
6.1 (3.1)
5.1 (4.0)
OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, re… 2026-10-03T15:30:24Z 2026-10-03T15:30:25Z
ghsa-875h-jw66-233j
6.1 (3.1)
5.3 (4.0)
OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenti… 2026-10-03T15:30:24Z 2026-10-03T15:30:24Z
ghsa-45wm-hvw4-223f
8.6 (3.1)
8.8 (4.0)
OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the… 2026-10-03T15:30:24Z 2026-10-03T15:30:24Z
ghsa-2w9f-mhfg-hq53
6.5 (3.1)
7.1 (4.0)
Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non-def… 2026-10-03T15:30:24Z 2026-10-03T15:30:24Z
ghsa-9xfm-37f4-2h8g
9.8 (3.1)
CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command … 2026-10-03T12:31:29Z 2026-10-03T12:31:29Z
ghsa-63c6-qprh-g95r
6.3 (3.1)
2.1 (4.0)
A vulnerability has been found in Linux Mint Xreader up to 4.6.9. Impacted is the function g_file_g… 2026-10-03T12:31:29Z 2026-10-03T12:31:29Z
ghsa-x42w-4gqh-qrvm
6.9 (4.0)
In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport recipien… 2026-10-03T09:31:18Z 2026-10-03T09:31:18Z
ghsa-rxw8-22c7-wgq6
5.9 (4.0)
In Bouncy Castle for Java before 1.86, HQC leaked secret-derived data through two side channels: it… 2026-10-03T09:31:18Z 2026-10-03T09:31:18Z
ghsa-jx8c-663q-ggc5
9.1 (3.1)
The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnera… 2026-10-03T09:31:18Z 2026-10-03T09:31:18Z
ghsa-jch3-5j66-88vx
9.2 (4.0)
In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation … 2026-10-03T09:31:18Z 2026-10-03T09:31:18Z
ghsa-jc55-7frr-fv5r
8.7 (4.0)
In Bouncy Castle for Java before 1.86, validation of an MLS (RFC 9420) external commit's proposal l… 2026-10-03T09:31:18Z 2026-10-03T09:31:18Z
ghsa-j453-27jp-4cph
8.7 (4.0)
In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a messag… 2026-10-03T09:31:18Z 2026-10-03T09:31:18Z
ghsa-hqqj-v58h-gr7x
8.7 (4.0)
In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle.pkix… 2026-10-03T09:31:18Z 2026-10-03T09:31:18Z
ghsa-gggh-4cvh-v637
7.1 (4.0)
In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so BLSPublicKeyParamet… 2026-10-03T09:31:18Z 2026-10-03T09:31:18Z
ghsa-f5wg-4mfp-h458
8.2 (4.0)
In Bouncy Castle for Java LTS before 2.73.13, the one-shot native packet ciphers for AES-CBC, CCM, … 2026-10-03T09:31:18Z 2026-10-03T09:31:18Z
ghsa-cwf6-pghv-hq93
8.2 (4.0)
In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by… 2026-10-03T09:31:18Z 2026-10-03T09:31:18Z
ghsa-8hgf-w73g-3x6v
8.2 (4.0)
In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no e… 2026-10-03T09:31:18Z 2026-10-03T09:31:18Z
ghsa-7hrr-mw36-px4x
8.2 (4.0)
In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-part… 2026-10-03T09:31:18Z 2026-10-03T09:31:18Z
ghsa-78x9-mjv2-rr3v
5.3 (4.0)
In Bouncy Castle for Java before 1.86, the raw JCA provider's legacy PBES1 (PKCS#5 scheme 1) and PK… 2026-10-03T09:31:18Z 2026-10-03T09:31:18Z
ghsa-5m53-wrr5-57qq
4.3 (3.1)
2.1 (4.0)
A flaw has been found in Linux Mint Xreader up to 4.6.5. This issue affects the function setup_docu… 2026-10-03T09:31:18Z 2026-10-03T09:31:18Z
ghsa-265f-7jp6-5v2f
6.4 (3.1)
The Twenty20 Image Before-After plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… 2026-10-03T09:31:18Z 2026-10-03T09:31:18Z