-
Notifications
You must be signed in to change notification settings - Fork 592
Pull requests: github/advisory-database
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[GHSA-4cc6-4h77-4425] KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow...
#7525
opened Apr 28, 2026 by
asrarmared-ship-it
Loading…
[GHSA-69cc-cv78-qc8g] Apache Tomcat: Configured cipher preference order not preserved
#7524
opened Apr 28, 2026 by
aruneko
Loading…
[GHSA-j39c-c8hj-x4j3] Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
#7523
opened Apr 28, 2026 by
hara-satoshi-ymr
Loading…
[GHSA-95jq-rwvf-vjx4] Apache Tomcat: CLIENT_CERT authentication does not fail as expected
#7522
opened Apr 28, 2026 by
aruneko
Loading…
[GHSA-653p-vg55-5652] Apache Tomcat Uncontrolled Resource Consumption vulnerability
#7521
opened Apr 28, 2026 by
yusuke-koyoshi
Loading…
[GHSA-344f-f5vg-2jfj] Potential remote code execution in Apache Tomcat
#7520
opened Apr 28, 2026 by
aruneko
Loading…
[GHSA-563x-q5rq-57qp] Apache Tomcat has an HTTP Request/Response Smuggling vulnerability
#7519
opened Apr 28, 2026 by
aruneko
Loading…
[GHSA-vf77-8h7g-gghp] Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat
#7518
opened Apr 28, 2026 by
aruneko
Loading…
[GHSA-q3mw-pvr8-9ggc] Apache Tomcat Open Redirect vulnerability
#7517
opened Apr 28, 2026 by
hara-satoshi-ymr
Loading…
[GHSA-qcxh-w3j9-58qr] Apache Tomcat Denial of Service vulnerability
#7516
opened Apr 28, 2026 by
aruneko
Loading…
[GHSA-24j9-x2wg-9qv6] Apache Tomcat: CLIENT_CERT authentication does not fail as expected
#7515
opened Apr 28, 2026 by
aruneko
Loading…
[GHSA-2mjp-6q6p-2qxm] Undici has an HTTP Request/Response Smuggling issue
#7514
opened Apr 28, 2026 by
tijuks
Loading…
[GHSA-x5gf-qvw8-r2rm] pm2 Regular Expression Denial of Service vulnerability
#7513
opened Apr 27, 2026 by
corridormatt
Loading…
Add GHSA-fhw2-h46x-v2mj: Arbitrary local file disclosure in @playwright/mcp
#7511
opened Apr 27, 2026 by
mmzha2013
Loading…
[GHSA-v92g-xgxw-vvmm] Mako: Path traversal via double-slash URI prefix in TemplateLookup
#7508
opened Apr 26, 2026 by
augustocesarperin
Loading…
[GHSA-rvhj-8chj-8v3c] Mflow: Command Injection when serving models with enable_mlserver=True
#7507
opened Apr 26, 2026 by
rotemd-apiiro
Loading…
[GHSA-qj8w-gfj5-8c6v] Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
#7506
opened Apr 26, 2026 by
sealonohana
Loading…
[GHSA-mw35-8rx3-xf9r] Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization
#7504
opened Apr 25, 2026 by
shakevsky
Loading…
[GHSA-cw7v-45wm-mcf2] Kirby CMS has Persistent DoS via Malformed Image Upload
#7503
opened Apr 24, 2026 by
lukasbestle
Loading…
[GHSA-x4p7-7chp-64hq] Keycloak: Unauthorized authentication via disabled SAML Identity Provider
#7502
opened Apr 24, 2026 by
sekveaja
Loading…
fix: correct GHSA-pfr9-2p92-qrhq dbn fixed version 0.22.0 -> 0.22.1
#7483
opened Apr 21, 2026 by
DEVSOG12
Loading…
fix: correct GHSA-4j5j-58j7-6c3w dulwich fixed version 0.9.9 -> 0.10.0
#7482
opened Apr 21, 2026 by
DEVSOG12
Loading…
[GHSA-9hxg-w7qf-hh93] Use Go pseudo-version for fixed version
#7477
opened Apr 21, 2026 by
cookesan
Loading…
[GHSA-mwv9-gp5h-frr4] Sveltejs devalue's
devalue.parse and devalue.unflatten emit objects with __proto__ own properties
#7464
opened Apr 20, 2026 by
Wenxin-Jiang
Loading…
Previous Next
ProTip!
Follow long discussions with comments:>50.