{"source":"github-security","name":"GitHub Security Advisories","kind":"widget","via":"native","records":[{"id":"GHSA-g685-9q2w-88f4","title":"The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to...","subtitle":"2026-07-25T09:30:24Z","value":"high","href":""},{"id":"GHSA-pw7g-jh5j-6w4m","title":"Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the...","subtitle":"2026-07-25T03:30:54Z","value":"high","href":""},{"id":"GHSA-c964-568j-vxx7","title":"Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE,...","subtitle":"2026-07-25T03:30:54Z","value":"high","href":""},{"id":"GHSA-f56p-33jj-44h8","title":"Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.","subtitle":"2026-07-25T00:31:48Z","value":"high","href":""},{"id":"GHSA-hgch-6f8j-3xgx","title":"Weintek cMT3092X HMI stores user account passwords in plaintext.","subtitle":"2026-07-25T00:31:48Z","value":"high","href":""},{"id":"GHSA-jmfc-m78f-w5vj","title":"The web management interface of Tycon Systems TPDIN-Monitor-WEB2\n\n does not perform server-side...","subtitle":"2026-07-25T00:31:47Z","value":"critical","href":""},{"id":"GHSA-8r5g-w376-c3rg","title":"An attacker can modify data that should be restricted to read‑only access.","subtitle":"2026-07-25T00:31:47Z","value":"high","href":""},{"id":"GHSA-fgcj-2p5v-hv7f","title":"Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.","subtitle":"2026-07-25T00:31:47Z","value":"high","href":""},{"id":"GHSA-848c-c2cx-j7qx","title":"NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in...","subtitle":"2026-07-25T00:31:47Z","value":"high","href":""},{"id":"GHSA-6vch-q96h-7gc3","title":"etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline","subtitle":"2026-07-24T22:40:16Z","value":"high","href":""},{"id":"GHSA-j6g5-3hh3-pgw8","title":"AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()","subtitle":"2026-07-24T22:38:56Z","value":"high","href":""},{"id":"GHSA-xg4h-6gfc-h4m8","title":"etcd: Watch API authorization bypass via open-ended range requests","subtitle":"2026-07-24T22:38:22Z","value":"high","href":""},{"id":"GHSA-jvxp-qmx7-gjpx","title":"Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service","subtitle":"2026-07-24T22:37:39Z","value":"high","href":""},{"id":"GHSA-hmj8-5xmh-5573","title":"libp2p: yamux connection DoS via oversized data frame","subtitle":"2026-07-24T22:37:17Z","value":"high","href":""},{"id":"GHSA-6xj8-qv9j-xcjq","title":"Oh My Posh: Arbitrary command execution via template injection in the path segment","subtitle":"2026-07-24T22:36:11Z","value":"high","href":""},{"id":"GHSA-fp43-vj7g-pg92","title":"OmniFaces: Forged combined-resource IDs and related output/push boundaries","subtitle":"2026-07-24T22:35:27Z","value":"high","href":""},{"id":"GHSA-gm3r-q2wp-hw87","title":"Shescape: Quadratic-time denial of service in the flag-protection","subtitle":"2026-07-24T22:35:08Z","value":"high","href":""},{"id":"GHSA-w4hw-qcx7-56pr","title":"Shescape: Shell injection via unescaped parentheses on Windows with CMD","subtitle":"2026-07-24T22:34:23Z","value":"critical","href":""},{"id":"GHSA-29w2-fq35-v728","title":"AWS API MCP Server Security Policy Bypass via Startup Initialization Failure","subtitle":"2026-07-24T22:33:19Z","value":"high","href":""},{"id":"GHSA-95cv-r8x4-vh75","title":"OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal","subtitle":"2026-07-24T22:29:08Z","value":"high","href":""},{"id":"GHSA-7ppr-r889-mcf2","title":"blaze: Unbounded WebSocket message aggregation in http4s-blaze-server","subtitle":"2026-07-24T22:28:05Z","value":"high","href":""},{"id":"GHSA-46q4-43ph-c6fr","title":"blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)","subtitle":"2026-07-24T22:26:48Z","value":"high","href":""},{"id":"GHSA-mhvj-jhpq-885v","title":"blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser","subtitle":"2026-07-24T22:26:27Z","value":"high","href":""},{"id":"GHSA-cmwh-g2h8-c222","title":"Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover","subtitle":"2026-07-24T21:56:02Z","value":"high","href":""},{"id":"GHSA-rm67-g9ch-vxff","title":"Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own","subtitle":"2026-07-24T21:55:15Z","value":"high","href":""},{"id":"GHSA-h4hf-v6w5-897x","title":"Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account","subtitle":"2026-07-24T21:54:55Z","value":"high","href":""},{"id":"GHSA-f25v-x6vr-962g","title":"Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password","subtitle":"2026-07-24T21:54:24Z","value":"critical","href":""},{"id":"GHSA-mh99-v99m-4gvg","title":"brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash","subtitle":"2026-07-24T21:53:14Z","value":"high","href":""},{"id":"GHSA-vh45-f885-3848","title":"sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock","subtitle":"2026-07-24T21:50:45Z","value":"critical","href":""},{"id":"GHSA-47w6-gwp4-w6vc","title":"vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review","subtitle":"2026-07-24T21:49:36Z","value":"high","href":""}],"count":30,"generated_at":"2026-07-25T12:24:00.402Z"}