Threats Tagged 'ghsa'
View all threats tagged with 'ghsa'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa'
Click on any threat for detailed analysis and mitigation recommendations
Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows an attacker to cause a denial of service via the libavformat/iamf_writer.c component (CVE-2026-52295)CVE-2026-52295 0 A buffer overflow vulnerability exists in Ffmpeg version 7.0 and later in the libavformat/iamf_writer.c component. This flaw can be exploited by an attacker to cause a denial of service (DoS) condition. The vulnerability does not impact confidentiality or integrity but affects availability. Join the discussion | GCVE Database | 09/01/2026, 18:30:46 UTC Added: 09/07/2026, 16:09:04 UTC |
Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. (CVE-2026-86342)CVE-2026-86342 0 MISP versions up to 2.5.45 have improper authorization checks in the freetext feed preview functionality. This flaw allows users to access correlated event attributes and feed metadata without proper access control, exposing restricted event information and feed URLs. The vulnerability arises because correlation queries do not enforce user ACLs or feed visibility restrictions correctly. Fixes address these issues by applying ACLs consistently, removing feed URLs from results, and restricting cross-feed data to visible feeds only. Join the discussion | GCVE Database | 09/07/2026, 09:31:40 UTC Added: 09/07/2026, 16:08:55 UTC |
A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. (CVE-2026-86294)CVE-2026-86294 0 SourceCodester Simple Traffic Offense System 1.0 contains a cross-site scripting (XSS) vulnerability in the save-settings.php file within the Settings Update Endpoint. This vulnerability arises from improper handling of the site_name and site_desc parameters, allowing remote attackers to inject malicious scripts. The vulnerability has a low severity score and requires user interaction for exploitation. No patch or official remediation information is currently provided. Join the discussion | GCVE Database | 09/07/2026, 12:30:29 UTC Added: 09/07/2026, 16:08:55 UTC |
Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute… (CVE-2026-78325)CVE-2026-78325 0 A cross-site scripting (XSS) vulnerability exists in the Evernote and Google Keep note importers in Standard Notes for Android versions through 3.201.24. This flaw allows an attacker to execute arbitrary JavaScript within the application context when a victim imports a specially crafted .enex or Google Keep HTML file. Exploitation can lead to theft of encryption keys and note data, as well as arbitrary invocation of native device APIs. Join the discussion | GCVE Database | 09/07/2026, 12:30:29 UTC Added: 09/07/2026, 16:08:55 UTC |
A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. (CVE-2026-86291)CVE-2026-86291 0 A SQL injection vulnerability exists in itsourcecode Sales and Inventory System 1.0 within the /pages/us_edit1.php file. The vulnerability allows remote attackers with low privileges to manipulate the ID argument, potentially leading to unauthorized data access or modification. The vulnerability has a CVSS 3.1 base score of 6.3, indicating a medium severity impact on confidentiality, integrity, and availability. No patch or remediation information is currently available, and no known exploits are reported in the wild. Join the discussion | GCVE Database | 09/07/2026, 12:30:29 UTC Added: 09/07/2026, 16:08:51 UTC |
Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile… (CVE-2026-86347)CVE-2026-86347 0 A vulnerability in affected versions of MISP (up to 2.5.45) allows any authenticated user to access the TemplatesController::uploadFile() function due to a wildcard ACL entry. This bypasses intended role restrictions, enabling low-privileged or read-only users to upload arbitrary files repeatedly, consuming server disk space. The uploaded files receive random names, are stored outside the web root, and are not served over HTTP, preventing arbitrary file overwrite, stored XSS, or remote code execution. Join the discussion | GCVE Database | 09/07/2026, 12:30:29 UTC Added: 09/07/2026, 16:08:51 UTC |
Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /. (CVE-2026-86351)CVE-2026-86351 0 MISP versions up to 2.5.45 have a vulnerability in the validation of the user-configurable homepage setting. The validation only checks if the path begins with a slash (/), which is insufficient because protocol-relative URLs starting with // can bypass this check and redirect users to external origins. This unsafe homepage value can be stored and later used in post-login routing, potentially leading to unsafe redirects. The vulnerability is identified as CVE-2026-86351 and is categorized as a moderate severity issue. Join the discussion | GCVE Database | 09/07/2026, 12:30:29 UTC Added: 09/07/2026, 16:08:51 UTC |
A vulnerability was detected in Linksys RE7000 2.0.15. (CVE-2026-86299)CVE-2026-86299 0 A high-severity vulnerability (CVE-2026-86299) exists in Linksys RE7000 version 2.0.15 affecting the PingTest Handler component. It allows remote attackers to perform OS command injection via manipulation of the pingTestIp, pingTestPktSize, or pingTestTimes parameters in the /cgi-bin/json.cgi?PingTest endpoint. The vulnerability has a CVSS score of 9.9, indicating critical impact on confidentiality, integrity, and availability. Exploit code is publicly available, but no known exploitation in the wild has been reported. No patch or official remediation information is currently provided. Join the discussion | GCVE Database | 09/07/2026, 12:30:29 UTC Added: 09/07/2026, 16:08:51 UTC |
A vulnerability was found in D-Link DIR-895L A1_102b07. (CVE-2026-86295)CVE-2026-86295 0 A command injection vulnerability exists in the sendACK function of the udhcpcd component in D-Link DIR-895L A1_102b07. The vulnerability arises from improper handling of the Hostname argument, allowing remote attackers to execute arbitrary commands. The exploit code has been publicly disclosed. The vulnerability has a CVSS score of 8.3, indicating a high severity impact on confidentiality, integrity, and availability. Join the discussion | GCVE Database | 09/07/2026, 12:30:29 UTC Added: 09/07/2026, 16:08:51 UTC |
A vulnerability was determined in D-Link DIR-822A A_101. (CVE-2026-86296)CVE-2026-86296 0 A critical stack-based buffer overflow vulnerability exists in the strcpy function of the udhcpcd component in D-Link DIR-822A A_101. This vulnerability can be exploited remotely without authentication, leading to complete compromise of confidentiality, integrity, and availability. Public exploit code is available, increasing the risk of exploitation. Join the discussion | GCVE Database | 09/07/2026, 12:30:29 UTC Added: 09/07/2026, 16:08:51 UTC |
Showing 1 to 10 of 6421 results