Security Advisory

# Advisory CVE Product Published
1 Session id path traversal in spiral/session leading to arbitrary file write GHSA-c84m-p8px-4wpx SpiralVendorSpiral 2026-07-17
2 █████ █████ higressVendorAlibaba -
3 █████ █████ go-zeroVendorgo-zero -
4 █████ █████ go-zeroVendorgo-zero -
5 unauthenticated remote admin via reverse-proxy + localhost-trust CVE-2026 GPUStackVendorGPUStack 2026-06-14
6 SSRF via `framework_config.pricing_url` in `/api/config` enables internal network reconnaissance and service banner disclosure CVE-2026-11574 BifrostVendorMaxim 2026-06-05
7 █████ █████ LighthouseVendorLighthouse -
8 Arbitrary file read in CDI importer via attacker-controlled qcow2 backing file █████ █████ -
9 phpMyFAQ vulnerable to stored XSS on attachments filename CVE-2024-24574 phpMyFAQVendorphpMyFAQ 2024-02-06
10 █████ █████ SpiralVendorSpiral -

© Nikko Enggaliano 2022 - 2026